ETExamTower
Q17Network Security, Compliance, and GovernanceMultiple answers

A company operates a hybrid cloud environment. Its data center connects to the AWS Cloud through an AWS Direct Connect connection. The AWS environment includes VPCs connected in a hub-and-spoke model by a transit gateway. The AWS environment uses a transit VIF with a Direct Connect gateway for on-premises connectivity. The company uses a hybrid DNS model. It has configured Amazon Route 53 Resolver endpoints in the hub VPC to permit bidirectional DNS traffic flow. The company runs a backend application in one of the VPCs. The company uses a message-oriented architecture and uses Amazon Simple Queue Service (Amazon SQS) to receive messages from other applications over a private network. A network engineer wants to use an interface VPC endpoint for Amazon SQS for this architecture. Client services must be able to access the endpoint service from on premises and from multiple VPCs in the company's AWS infrastructure. Which combination of actions should the network engineer take to ensure that the client applications can resolve DNS for the interface endpoint? (Choose three.)

Select 3 answers.
← → navigate · a answer
Community votes
C
27% (12)
B
24% (11)
F
18% (8)
E
16% (7)
A
9% (4)
D
7% (3)
Discussion · 22
B, C, F 18
Its internal and the access should be private ,which makes F correct
15
To access interface endpoints through other VPCs, we need to - 1. Disable private DNS for VPC endpoints 2. Create PHZ e.g. sqs.us-east-1.amazonaws.com 3. Create Alias record pointing to VPC endpoint DNS 4. Associate PHZ with all the spoke VPCs Hence, answer is B), C) & E)
B, C, F 2
B, C & F Public DNS Name (sqs.us-east-1.amazonaws.com) This is the standard public AWS SQS endpoint. It routes traffic over the public internet. It can be accessed from anywhere, including VPCs and on-premises networks, but requires internet access or AWS PrivateLink. Private DNS Name (.sqs.us-east-1.vpce.amazonaws.com) This is the private endpoint for SQS, which is available when you create an AWS PrivateLink interface endpoint for SQS. It allows access to SQS entirely within the AWS network (without going over the public internet). Only accessible from within the VPC or from on-premises via a VPN or Direct Connect to AWS.
B, C, E 2
BCE With C) you create the private hosted zone for sqs.us-east-1.amazonaws.com that is basically the PUBLIC DNS name of SQS service, and associate the VPCs with this private zone. Then, you MUST use that public name, because that's the one that you have created in your private zone! You didn't create a zone for sqs.us-east-1.vpce.amazonaws.com! Thus it's E and not F.
2
That's correct aws.amazon.com/blogs/networking-and-content-delivery/centralize-access-using-vpc-interface-endpoints/
A, D, F 2
A enables private DNS resolution, allowing clients to use the standard service name (sqs.us-east-1.amazonaws.com) and have it resolve to the private IP of the interface endpoint. D leverages the automatically created private hosted zone, reducing operational overhead and ensuring consistency. F confirms that clients can use the private DNS name for direct access, which is necessary for hybrid environments with DNS forwarding.
1
BCE public DNS name will be resolve to interface endpoint private IP finally Also, options B and F are indeed in conflict: If we turn off private DNS names (option B), the interface endpoint won't have a private DNS name to use, making option F impossible.
B, C, E 1
We created the PRIVATE hosted zone.
1
Sorry, I chose wrong. BCF is right.
B, C, E 1
BCE https://aws.amazon.com/blogs/networking-and-content-delivery/centralize-access-using-vpc-interface-endpoints/ If you want to resolve the AWS service endpoint natively from within spoke VPCs, then you must perform these additional steps: Disable the Private DNS for an interface VPC endpoint in the hub VPC (if it’s enabled). Create a Private Hosted Zone with same name as AWS service endpoint (for example, sqs.us-east-1.amazonaws.com) and create an A record (alias) to point to an interface VPC endpoint DNS.
1
B,C,E!
1
BCF It's so obvious. Why you choose E?
1
B turns off private dns meaning that the automatic private hosted zone that resolves the public name to the private ip won’t be created.
B, C, F 1
E: Using the public DNS name would not leverage the private interface endpoint and could potentially route traffic over the public internet, which is not desired in this private network setup.
A, C, E 1
ACE, The question asks about combination of step so what is the point of manually create private hosted zone if you don't use the record.
A, D, F 1
I think....
A, D, F 1
There's direct connect so no need for public DNS. There are resolver endpoints for onprem bidir DNS. D associates the auto created zone with the other vpcs. F is thus possible.
B, C, E 1
BCE...................
1
Hello, does the letter E speak about public DNS? But in this case wouldn't it be correct to use private DNS? So the letter F instead of E?
B, C, F 1
These options complement each other and provide a complete solution for resolving DNS for the interface endpoint: Option B disables private DNS names, which would prevent client applications from accessing the SQS endpoint. This option is not recommended. Option C manually creates a private hosted zone and associates it with other VPCs or uses the automatically created one provided by Amazon SQS. This ensures that client applications can resolve DNS for the interface endpoint. Option F provides the correct format for using the private DNS name of the interface endpoint (in this case, .sqs.us-east-1.vpce.amazonaws.com).
B, C, E 1
https://aws.amazon.com/es/blogs/networking-and-content-delivery/centralized-dns-management-of-hybrid-cloud-with-amazon-route-53-and-aws-transit-gateway/
B, C, F 1
with the Private DNS enabled, private hosted will be created automatically but it will not be visible nor associated with other vpcs. Even with the DNS enabled, from the on-premises side we have to write DNS forwarder rule to forward domain to sqs.us-east-1.amazonaws.com to AWS VPC .2 IP address or IP address if any inbound rules in route53. I will be with the BCF