Professional Cloud Security EngineerConfiguring network securityEasy

A company is using Cloud DNS for their domain management and has recently migrated several services to a new Google Cloud project. They need to ensure that internal applications within their VPC can resolve hostnames for these new services, but these hostnames should not be resolvable from the public internet. Which Cloud DNS feature should be configured?

  1. ACloud DNS response policy zones
  2. BCloud DNS public zones
  3. CCloud DNS forwarding zones
  4. DCloud DNS private zones
Show answer & explanation

Correct answer: D. Cloud DNS private zones

Cloud DNS private zones allow you to manage DNS records for internal resources within your VPC networks, ensuring that these hostnames are resolvable only from within the specified VPCs and not from the public internet.

Why the other options are wrong

  • A. Cloud DNS response policy zones allow for custom responses to DNS queries, but a private zone is the primary mechanism for internal-only resolution.
  • B. Cloud DNS public zones are for publicly resolvable domains, which contradicts the requirement of not being resolvable from the public internet.
  • C. Cloud DNS forwarding zones redirect queries to other DNS servers and don't inherently restrict public access to internal hostnames.

Cloud DNS Private Zones

Cloud DNS private zones enable DNS resolution for internal resources within Google Cloud VPC networks, making hostnames resolvable only from within those networks.

  • Internal-only DNS resolution
  • Associated with one or more VPCs
  • Not resolvable from the public internet

Memory trick: DNS zones are like phone books, some are public, some are private.

More Configuring network security questions