Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SOA-C03 Exam - Topic 3 Question 17 Discussion

A company operates compute resources in a VPC and in the company's on-premises data center. The company already has an AWS Direct Connect connection between the VPC and the on-premises data center.A CloudOps engineer needs to ensure that Amazon EC2 instances in the VPC can resolve DNS names for hosts in the on-premises data center.Which solution will meet this requirement with the LEAST amount of ongoing maintenance?
B) Create an Amazon Route 53 Resolver outbound endpoint. Add the IP addresses of an on-premises DNS server for the domain names that need to be forwarded.
A) Create an Amazon Route 53 private hosted zone. Populate the zone with the hostnames and IP addresses of the hosts in the on-premises data center.
C) Set up a forwarding rule for reverse DNS queries in Amazon Route 53 Resolver. Set the enableDnsHostnames attribute to true for the VPC.
D) Add the hostnames and IP addresses for the on-premises hosts to the /etc/hosts file of each EC2 instance.

Amazon SOA-C03 Exam - Topic 3 Question 17 Discussion

Actual exam question for Amazon's SOA-C03 exam
Question #: 17
Topic #: 3
[All SOA-C03 Questions]

A company operates compute resources in a VPC and in the company's on-premises data center. The company already has an AWS Direct Connect connection between the VPC and the on-premises data center.

A CloudOps engineer needs to ensure that Amazon EC2 instances in the VPC can resolve DNS names for hosts in the on-premises data center.

Which solution will meet this requirement with the LEAST amount of ongoing maintenance?

Show Suggested Answer Hide Answer
Suggested Answer: B

Amazon Route 53 Resolver outbound endpoints enable Amazon VPC resources to forward DNS queries to DNS servers that are outside of AWS, such as on-premises DNS servers. Because the company already has AWS Direct Connect in place, DNS queries can be routed privately from the VPC to the on-premises DNS infrastructure without using the public internet.

By creating an outbound endpoint and configuring forwarding rules for the on-premises domains, EC2 instances in the VPC can resolve DNS names dynamically using the existing authoritative DNS servers. This approach requires minimal ongoing maintenance because DNS records continue to be managed centrally in the on-premises DNS system.

Manually populating a private hosted zone or /etc/hosts files would require constant updates and does not scale. Reverse DNS forwarding alone does not solve forward name resolution.

Therefore, using Route 53 Resolver outbound endpoints is the correct solution.


Contribute your Thoughts:

0/2000 characters
I feel like D is too much work. Each instance? No thanks!
upvoted 0 times
...
Margot
5 days ago
Option A sounds good too, but updating the zone can be a hassle.
upvoted 0 times
...
Ines
10 days ago
Agreed! Outbound endpoints are easier to manage.
upvoted 0 times
...
An
15 days ago
I think option B is the best. It requires less manual work later.
upvoted 0 times
...
Daniel
21 days ago
I think B is the way to go, it’s more scalable for future changes.
upvoted 0 times
...
Gracia
26 days ago
Wait, can EC2 really resolve on-prem DNS like that? Sounds too easy!
upvoted 0 times
...
Lizette
1 month ago
D is just outdated, who wants to edit every instance's hosts file?
upvoted 0 times
...
Luz
1 month ago
I disagree, A could work too, but it requires more manual updates.
upvoted 0 times
...
Catalina
1 month ago
Option B seems like the best choice for minimal maintenance.
upvoted 0 times
...
Irma
2 months ago
B is definitely the way to go, less hassle in the long run!
upvoted 0 times
...
Lisbeth
2 months ago
I think C is overcomplicating things for a simple DNS issue.
upvoted 0 times
...
Leota
2 months ago
Wow, I didn't realize the /etc/hosts method was still a thing!
upvoted 0 times
...
Delmy
2 months ago
I disagree, A could work too, but it requires more manual updates.
upvoted 0 times
...
Sabine
2 months ago
Option B seems like the best choice for minimal maintenance.
upvoted 0 times
...
Buddy
2 months ago
Option D seems like a quick fix, but I doubt it would be practical for a larger environment with many EC2 instances.
upvoted 0 times
...
Andra
3 months ago
I recall something about Route 53 Resolver, but I'm uncertain if option C is the best choice for this scenario.
upvoted 0 times
...
Josefa
3 months ago
I'm not entirely sure, but I feel like option A might require more maintenance since you'd have to keep the hosted zone updated manually.
upvoted 0 times
...
Nicolette
3 months ago
I think option B sounds familiar; I remember it being mentioned in a practice question about DNS resolution between VPC and on-premises.
upvoted 0 times
...

Save Cancel