AWS Certified Solutions Architect – ProfessionalDesign Solutions for Organizational ComplexityHard

A global media company operates a content delivery platform with a mix of on-premises and AWS resources. They need to implement a robust, highly available, and secure solution for managing DNS resolution across their hybrid environment. The solution must allow on-premises clients to resolve DNS queries for AWS resources (e.g., EC2 instances, RDS endpoints) using their existing on-premises DNS servers, and AWS resources to resolve DNS queries for on-premises resources. They also need to ensure that specific DNS queries for a custom domain (e.g., internal.example.com) are routed directly to on-premises DNS servers, without exposing the entire on-premises network to AWS. Which AWS service combination should be recommended?

  1. AUse Amazon Route 53 private hosted zones for AWS resources and public hosted zones for on-premises resources.
  2. BConfigure custom DNS servers on Amazon EC2 instances in AWS and update DHCP option sets.
  3. CDeploy AWS Route 53 Resolver endpoints in the AWS VPCs and configure conditional forwarding on on-premises DNS servers.
  4. DEstablish a full mesh of VPC peering connections and configure DNS forwarding rules on each EC2 instance.
Show answer & explanation

Correct answer: C. Deploy AWS Route 53 Resolver endpoints in the AWS VPCs and configure conditional forwarding on on-premises DNS servers.

AWS Route 53 Resolver endpoints enable hybrid DNS resolution. Inbound endpoints allow on-premises DNS servers to forward queries for AWS resources to Route 53. Outbound endpoints allow AWS resources to forward queries for on-premises resources to on-premises DNS servers. Conditional forwarding on on-premises DNS servers for specific domains ensures security and controlled access, meeting all requirements.

Why the other options are wrong

  • A. Route 53 private hosted zones are for AWS resources, but public hosted zones for on-premises resources expose internal details and do not provide the hybrid forwarding mechanism required for seamless resolution between environments.
  • B. Configuring custom DNS servers on EC2 instances adds operational overhead and complexity, and does not provide the integrated hybrid resolution capabilities of Route 53 Resolver.
  • D. A full mesh of VPC peering connections is for network connectivity, not DNS resolution, and configuring DNS forwarding on each EC2 instance is unmanageable and not scalable.

AWS Route 53 Resolver Endpoints for Hybrid DNS

A feature of Amazon Route 53 that enables seamless DNS query resolution between VPCs and on-premises networks without direct exposure of entire networks.

  • Inbound endpoints allow on-premises DNS to resolve AWS DNS names.
  • Outbound endpoints allow AWS resources to resolve on-premises DNS names.
  • Supports conditional forwarding rules for specific domain resolution.
  • Provides highly available and scalable hybrid DNS resolution.

Memory trick: Route 53 Resolver is the smart traffic cop for hybrid DNS queries.

More Design Solutions for Organizational Complexity questions