Professional Cloud Security EngineerConfiguring network securityMedium
A large enterprise is migrating its on-premises applications to Google Cloud. They have a complex internal DNS infrastructure with thousands of records that need to be resolvable from their Google Cloud VPC networks without exposing them to the public internet. The enterprise also needs to manage these records centrally and ensure consistent resolution across hybrid environments. Which Google Cloud service should they use?
- ACloud CDN with DNS integration
- BCloud DNS Private Zones with DNS Peering
- CExternal DNS with custom DNS servers
- DCloud DNS Public Zones
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud DNS Private Zones with DNS Peering
Cloud DNS Private Zones allow you to serve DNS records for your private networks. When combined with DNS Peering, these private zones can be made resolvable from other VPC networks, including those connected via VPN or Interconnect to on-premises, providing central management and hybrid resolution without public exposure.
Why the other options are wrong
- A. Cloud CDN is for content delivery, not for managing or resolving internal DNS records.
- C. External DNS with custom DNS servers would require managing custom infrastructure, which is less integrated and scalable than Cloud DNS.
- D. Cloud DNS Public Zones are for public-facing domains and would expose internal records to the internet.
Cloud DNS Private Zones & Peering
Private DNS zones in Google Cloud for internal-only resolution, which can be shared across VPCs using DNS peering.
- Resolves internal domain names within VPC networks
- DNS Peering allows private zones to be queried from other peered VPCs
- Supports hybrid cloud DNS resolution when combined with Cloud VPN/Interconnect
Memory trick: Your private DNS, everywhere, securely.