AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium

A large enterprise with a complex hybrid cloud environment needs to resolve DNS queries for both on-premises resources (using Windows DNS servers) and AWS resources (within VPCs). They require a highly available and secure solution that allows EC2 instances in AWS to resolve on-premises hostnames and on-premises servers to resolve private DNS names of AWS resources. Which AWS service and configuration should be used to achieve this bidirectional DNS resolution?

  1. AAmazon Route 53 Resolver Endpoints (Inbound and Outbound)
  2. BAmazon Route 53 Public Hosted Zones with Conditional Forwarders on-premises
  3. CCustom DNS servers deployed in EC2 instances with VPC Peering
  4. DAWS Directory Service for Microsoft Active Directory with DNS integration
Show answer & explanation

Correct answer: A. Amazon Route 53 Resolver Endpoints (Inbound and Outbound)

Route 53 Resolver Endpoints (Inbound and Outbound) are specifically designed for hybrid DNS resolution. Outbound endpoints forward DNS queries from AWS VPCs to on-premises DNS servers, while Inbound endpoints allow on-premises DNS servers to forward queries to AWS for private DNS resolution. This provides a robust, highly available, and secure bidirectional resolution mechanism.

Why the other options are wrong

  • B. Public hosted zones are for public domain names, not private hybrid resolution, and conditional forwarders alone won't enable bidirectional resolution without AWS-side integration.
  • C. Custom DNS servers in EC2 are complex to manage, maintain high availability, and secure compared to the managed Route 53 Resolver Endpoints solution.
  • D. While Directory Service integrates with DNS, it's primarily for identity management and not the core service for general bidirectional hybrid DNS resolution for all AWS private resources.

Route 53 Resolver Endpoints

A feature of Amazon Route 53 Resolver that enables hybrid DNS resolution between AWS VPCs and on-premises DNS servers, supporting both inbound (on-prem to AWS) and outbound (AWS to on-prem) queries.

  • Inbound endpoints: on-premises queries resolve AWS private DNS.
  • Outbound endpoints: AWS queries resolve on-premises DNS.
  • Highly available and scalable managed service.
  • Uses ENIs in your VPC for network connectivity.

Memory trick: Resolver Endpoints: The two-way street for hybrid DNS.

More Network Design questions