AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium
An organization is deploying a new application that uses a custom DNS domain, example.internal, for internal service discovery. The application will run on EC2 instances in a private subnet within a VPC. The organization also has an on-premises data center that needs to resolve these internal DNS names. What is the most appropriate solution to enable DNS resolution for example.internal from on-premises to AWS?
- ACreate a new DNS server on an EC2 instance in the VPC and configure on-premises to use it.
- BConfigure a Route 53 Public Hosted Zone for example.internal.
- CSet up a Route 53 Resolver Inbound Endpoint in the VPC.
- DUse a Route 53 Outbound Endpoint to forward requests from AWS to on-premises DNS.
Show answer & explanationAnswer & explanation
Correct answer: C. Set up a Route 53 Resolver Inbound Endpoint in the VPC.
A Route 53 Resolver Inbound Endpoint allows DNS queries originating from on-premises networks to be resolved by the Route 53 Resolver within your VPC. This enables on-premises resources to resolve DNS records in your private hosted zones or VPC-specific DNS names, such as those for EC2 instances.
Why the other options are wrong
- A. While possible, deploying and managing a custom DNS server adds operational overhead and complexity compared to using AWS managed services like Route 53 Resolver.
- B. A Public Hosted Zone is for public DNS resolution, not for private internal domains accessible from on-premises.
- D. An Outbound Endpoint is used for AWS resources to resolve DNS names from on-premises DNS servers, which is the opposite direction of the requirement.
Route 53 Resolver Inbound Endpoint
A feature of Route 53 Resolver that allows DNS queries from on-premises networks to be resolved by the VPC's Route 53 Resolver.
- Enables hybrid DNS resolution (on-premises to AWS).
- Resolves private hosted zones and VPC-specific DNS names.
- Requires IP addresses in your VPC for DNS forwarding.
Memory trick: Inbound is for inquiries 'In' to AWS from on-prem.