AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium
A company is migrating an on-premises application to AWS. The application uses a custom DNS suffix, `corp.example.com`, for internal services. The AWS environment consists of multiple VPCs, and the company wants to ensure that EC2 instances in these VPCs can resolve both public domain names and the internal `corp.example.com` names without using custom DNS servers on each instance. The internal DNS records for `corp.example.com` are managed by an on-premises DNS server located in the corporate data center. Which AWS networking service should be configured to enable this hybrid DNS resolution?
- AAWS Transit Gateway with DNS forwarding rules.
- BAmazon Route 53 Resolver with an Inbound Endpoint and an Outbound Endpoint.
- CVPC Endpoint Services configured for private DNS resolution.
- DAWS Direct Connect with a private virtual interface and custom DNS settings on EC2 instances.
Show answer & explanationAnswer & explanation
Correct answer: B. Amazon Route 53 Resolver with an Inbound Endpoint and an Outbound Endpoint.
Amazon Route 53 Resolver (formerly known as Amazon DNS) with an Inbound Endpoint allows on-premises DNS servers to query AWS-hosted private zones. An Outbound Endpoint allows AWS resources to query on-premises DNS servers for custom domains, making it the ideal solution for hybrid DNS resolution.
Why the other options are wrong
- A. AWS Transit Gateway helps with inter-VPC and hybrid connectivity but does not directly handle DNS resolution forwarding rules in this manner.
- C. VPC Endpoint Services are for privately accessing AWS services or services hosted by other AWS accounts, not for hybrid DNS resolution to on-premises DNS servers.
- D. While Direct Connect provides the connectivity, relying on custom DNS settings on each EC2 instance is not scalable or maintainable for a large environment and doesn't provide a centralized resolution mechanism.
Route 53 Resolver Endpoints
Route 53 Resolver Endpoints enable hybrid DNS resolution by allowing DNS queries to flow between your VPCs and your on-premises network.
- Inbound Endpoints allow on-premises DNS servers to query private hosted zones in Route 53.
- Outbound Endpoints allow AWS resources to query on-premises DNS servers for specific domains.
- They use ENIs in your VPC and require security groups for access control.
Memory trick: Route 53 Resolver: The bridge for names, both near and far.