AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignHard

A large manufacturing company has a hybrid cloud environment, with critical applications running both on-premises and in AWS. They need to ensure that their on-premises users can consistently resolve DNS records for AWS resources, including private hosted zones, and that AWS applications can resolve on-premises DNS records. The solution must be fault-tolerant and highly available. Which AWS service provides the most robust solution for this bidirectional DNS resolution?

  1. AEstablishing a VPN connection and manually configuring `/etc/hosts` files.
  2. BDeploying a DNS forwarder on an EC2 instance in each VPC.
  3. CUtilizing Amazon Route 53 Resolver Endpoints (Inbound and Outbound).
  4. DConfiguring public DNS records in Route 53 for all AWS resources.
Show answer & explanation

Correct answer: C. Utilizing Amazon Route 53 Resolver Endpoints (Inbound and Outbound).

Amazon Route 53 Resolver Endpoints (Inbound and Outbound) are explicitly designed for highly available and fault-tolerant bidirectional DNS resolution between on-premises networks and AWS VPCs. Inbound endpoints handle queries from on-premises to AWS private zones, while Outbound endpoints forward queries from AWS to on-premises DNS servers.

Why the other options are wrong

  • A. Manually configuring `/etc/hosts` files is unscalable, error-prone, and provides no fault tolerance or dynamic updates.
  • B. Deploying custom DNS forwarders on EC2 instances is not fault-tolerant, requires significant management overhead, and is not a managed AWS service for hybrid DNS.
  • D. Using public DNS records for internal AWS resources is a security risk and doesn't address resolving on-premises records from AWS.

Route 53 Resolver Endpoints (Hybrid DNS)

AWS Route 53 Resolver Endpoints enable secure, highly available, and scalable bidirectional DNS resolution between on-premises DNS servers and Amazon VPCs.

  • Inbound endpoints for on-premises to AWS resolution
  • Outbound endpoints for AWS to on-premises resolution
  • Managed service, highly available and fault-tolerant
  • Eliminates need for custom DNS infrastructure

Memory trick: Resolver Endpoints bridge your DNS worlds securely.

More Network Design questions