AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium
A global enterprise uses AWS for its applications and has a complex hybrid cloud environment. They need to ensure that DNS resolution for internal, on-premises resources (e.g., internalapp.corp.com) works seamlessly from EC2 instances in their AWS VPCs. They also have a Route 53 private hosted zone for AWS-internal applications (e.g., awsapp.internal). Which AWS service should be configured to allow EC2 instances to resolve on-premises DNS records without modifying instance configurations?
- ARoute 53 Public Hosted Zone
- BVPC DNS Resolution
- CRoute 53 Resolver Outbound Endpoint
- DRoute 53 Resolver Inbound Endpoint
Show answer & explanationAnswer & explanation
Correct answer: C. Route 53 Resolver Outbound Endpoint
A Route 53 Resolver Outbound Endpoint allows EC2 instances in a VPC to forward DNS queries for specified domains to on-premises DNS servers. This enables seamless resolution of on-premises resources.
Why the other options are wrong
- A. Public Hosted Zones are for public internet domains and cannot resolve private on-premises records.
- B. VPC DNS Resolution is for resolving AWS-provided DNS or Private Hosted Zones within the VPC but cannot forward queries to on-premises servers without a Resolver Endpoint.
- D. An Inbound Endpoint allows on-premises DNS servers to query AWS Private Hosted Zones, which is the opposite direction of the requirement.
Route 53 Resolver Outbound Endpoint
A Route 53 Resolver Outbound Endpoint allows DNS queries originating from within a VPC to be conditionally forwarded to on-premises DNS servers for specific domains.
- Enables resolution of on-premises DNS records from VPCs
- Requires specifying forwarding rules for target domains
- Deployed in private subnets with ENIs
- Integrates with Route 53 Resolver rules
Memory trick: Outbound Resolver is the bridge for AWS VPCs to ask on-prem about domains.