AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium

A financial institution needs to establish a highly available and secure hybrid DNS resolution strategy. On-premises applications must resolve AWS internal hostnames (e.g., EC2 private IPs), and AWS applications must resolve on-premises hostnames. The solution must not expose internal DNS resolvers to the public internet.

  1. AConfiguring public Route 53 hosted zones for both AWS and on-premises domains.
  2. BUsing Route 53 Resolver Endpoints for inbound and outbound queries.
  3. CImplementing conditional forwarders on existing DNS servers pointing to public DNS.
  4. DDeploying custom DNS servers in AWS and on-premises, synchronizing records.
Show answer & explanation

Correct answer: B. Using Route 53 Resolver Endpoints for inbound and outbound queries.

Route 53 Resolver Endpoints (Inbound and Outbound) provide a robust hybrid DNS solution. Inbound endpoints allow on-premises DNS servers to forward queries for AWS resources to Route 53. Outbound endpoints allow VPCs to forward queries for on-premises resources to on-premises DNS servers, all over private connections like Direct Connect or VPN.

Why the other options are wrong

  • A. Public hosted zones expose internal hostnames and are not suitable for private hybrid DNS resolution.
  • C. Conditional forwarders to public DNS would not resolve internal hostnames and expose internal DNS, violating security requirements.
  • D. Deploying and synchronizing custom DNS servers is complex, prone to errors, and difficult to scale compared to managed services.

Route 53 Resolver Endpoints

Managed services that allow DNS queries to be forwarded between your VPCs and your on-premises DNS servers.

  • Inbound endpoints: on-premises queries to AWS.
  • Outbound endpoints: AWS queries to on-premises.
  • Operates over private connections (Direct Connect/VPN).

Memory trick: Route 53 Resolves DNS privately, like a trusted endpoint.

More Network Design questions