AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignHard

A large manufacturing company has a hybrid cloud environment, with critical applications running both on-premises and in AWS. They need to ensure seamless DNS resolution for all resources, regardless of their location. Specifically, AWS resources must be able to resolve on-premises DNS records, and on-premises resources must be able to resolve AWS private DNS records (e.g., those in Route 53 private hosted zones). Which AWS service combination provides this bi-directional, hybrid DNS resolution?

  1. AAWS PrivateLink with custom DNS servers in each VPC.
  2. BAmazon Route 53 public hosted zones with conditional forwarding.
  3. CAWS Global Accelerator with Route 53 DNS Failover.
  4. DAmazon Route 53 Resolver endpoints and conditional forwarding rules.
Show answer & explanation

Correct answer: D. Amazon Route 53 Resolver endpoints and conditional forwarding rules.

Route 53 Resolver endpoints (Inbound and Outbound) enable bi-directional DNS resolution between on-premises and AWS. Inbound endpoints allow on-premises DNS servers to query private hosted zones in AWS. Outbound endpoints allow VPCs to forward queries for on-premises domains to specific on-premises DNS servers, completing the hybrid DNS loop.

Why the other options are wrong

  • A. PrivateLink is for private service connectivity, not DNS resolution, and custom DNS servers would require complex manual configuration and management.
  • B. Public hosted zones are for public domain resolution, and conditional forwarding alone doesn't provide the full bi-directional hybrid resolution without Resolver endpoints.
  • C. Global Accelerator improves application performance and Route 53 DNS Failover is for high availability of public DNS, neither addresses bi-directional hybrid DNS resolution.

Route 53 Resolver Endpoints (Hybrid DNS)

A feature of Amazon Route 53 Resolver that enables bi-directional DNS queries between your VPCs and your on-premises network. It uses Inbound endpoints for on-premises to AWS resolution and Outbound endpoints for AWS to on-premises resolution.

  • Enables seamless DNS resolution across hybrid environments.
  • Inbound endpoints allow on-premises DNS to query AWS private hosted zones.
  • Outbound endpoints allow AWS VPCs to query on-premises DNS servers.
  • Uses conditional forwarding rules for specific domains.
  • Requires network connectivity (e.g., Direct Connect or VPN) between on-premises and AWS.

Memory trick: Route 53 Resolver: Your 'DNS Bridge' for Hybrid Cloud.

More Network Design questions