AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A global enterprise uses AWS for its applications and has a complex hybrid cloud environment. They need to ensure that DNS resolution for internal, on-premises resources (e.g., internalapp.corp.com) works seamlessly from EC2 instances in their AWS VPCs. They also have a Route 53 private hosted zone for AWS-internal applications (e.g., awsapp.internal). Which AWS service should be configured to allow EC2 instances to resolve on-premises DNS records without modifying instance configurations?

  1. ARoute 53 Public Hosted Zone
  2. BVPC DNS Resolution
  3. CRoute 53 Resolver Outbound Endpoint
  4. DRoute 53 Resolver Inbound Endpoint
Show answer & explanation

Correct answer: C. Route 53 Resolver Outbound Endpoint

A Route 53 Resolver Outbound Endpoint allows EC2 instances in a VPC to forward DNS queries for specified domains to on-premises DNS servers. This enables seamless resolution of on-premises resources.

Why the other options are wrong

  • A. Public Hosted Zones are for public internet domains and cannot resolve private on-premises records.
  • B. VPC DNS Resolution is for resolving AWS-provided DNS or Private Hosted Zones within the VPC but cannot forward queries to on-premises servers without a Resolver Endpoint.
  • D. An Inbound Endpoint allows on-premises DNS servers to query AWS Private Hosted Zones, which is the opposite direction of the requirement.

Route 53 Resolver Outbound Endpoint

A Route 53 Resolver Outbound Endpoint allows DNS queries originating from within a VPC to be conditionally forwarded to on-premises DNS servers for specific domains.

  • Enables resolution of on-premises DNS records from VPCs
  • Requires specifying forwarding rules for target domains
  • Deployed in private subnets with ENIs
  • Integrates with Route 53 Resolver rules

Memory trick: Outbound Resolver is the bridge for AWS VPCs to ask on-prem about domains.

More Network Implementation questions