ETExamTower
Q24Network DesignMultiple answers

A company provides applications over the internet. An Amazon Route 53 public hosted zone serves as the authoritative DNS service for the company and its internet applications, which are all offered under the same domain name. A network engineer is developing a new version of one application. Every application component is hosted in the AWS Cloud. The application uses a three-tier architecture. Its front end is served by Amazon EC2 instances deployed in public subnets and assigned Elastic IP addresses. Its backend components are deployed in private subnets using RFC1918 addresses. Application components must be able to access other components within the application's VPC by using the same host names that are used on the public internet. The network engineer must also support future DNS changes, including adding new host names or retiring DNS entries. Which combination of steps will satisfy these requirements? (Choose three.)

Select 3 answers.
← → navigate · a answer
Community votes
B
33% (11)
C
30% (10)
D
21% (7)
E
15% (5)
A
0% (0)
F
0% (0)
Discussion · 29
B, C, D 12
Correct Answer: BCD B - you need a priavte hosted zone to resolve the same names to private IPs C - this one is tricky but you really need both of the DNS options enbaled in the VPC (enableDnsHostnames and enableDnsSupport) https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html#vpc-dns-hostnames "If you use custom DNS domain names defined in a private hosted zone in Amazon Route 53, or use private DNS with interface VPC endpoints (AWS PrivateLink), you must set both the enableDnsHostnames and enableDnsSupport attributes to true." D - This is correct A - wrong - no need to explain E - Nobody is asking to autmoate the process F - This will simply not work as you need records to resolve to both private nad poublic, yu must have two zones
B, C, D 5
BC are sure. I think the tricky options are D & E. Description mentions future changes, D means change manually. E means change automatically. D mentions add private IP in private hosted zone. E mentions change private hosted zone based on change on public hosted zone. Here, how does E accommodate the value in private hosted zone? Request information of public hosted zone only has public IP, we should not use this in private hosted zone. E doesn't mentioned accommodation even it has automation. So I prefer D.
4
What about this: "The network engineer also needs to accommodate future DNS changes, such as the introduction of new host names or the retirement of DNS entries."
4
B is correct C is correct D is correct E is also correct But the question has this part: "The network engineer also needs to accommodate future DNS changes, such as the introduction of new host names or the retirement of DNS entries." so I think I'll go with BCE
3
BCE, Option E will meet the requirement for future DNS changes
B, C, E 3
The network engineer also needs to accommodate future DNS changes, such as the introduction of new host names or the retirement of DNS entries. There needs to be an automated process to update new records - BCE is correct
3
B, D, E
3
Accommodate != automate
B, C, E 3
B. Creating a Route 53 private hosted zone for the same domain name and associating the application's VPC with the new private hosted zone allows internal DNS resolution within the VPC. C. Enabling DNS hostnames for the application's VPC is necessary for DNS resolution within the VPC. E. Creating an Amazon EventBridge rule triggered by AWS CloudTrail logs for Route 53 API calls and using an AWS Lambda function allows for automated updates to the private hosted zone when changes occur in the public hosted zone. This ensures that changes in the public DNS are reflected in the private DNS for internal resolution.
2
E will not work properly because it is copying public IP addresses from the public hosted zone and adding it to private hosted zone. Private hosted zone should use internal private IPs not public
2
E will not work properly because it is copying public IP addresses from the public hosted zone and adding it to private hosted zone. Private hosted zone should use internal private IPs not public
B, C, E 2
Step Function B Private hosted zone for internal resolution of the same hostnames C Enable DNS in the VPC for internal resolution E Automate synchronization with the public zone using EventBridge + Lambda
2
I think C is not needed because is not asking to resolve he hosts names, but the application DNS records. Meanwhile, E is needed to automated the updates
2
While E might allow for some level of automation in updating DNS records, it's complex and involves CloudWatch Events and Lambda functions. Additionally, it doesn't address the core requirement of allowing components within the same VPC to access each other using the same hostnames.
B, C, D 2
B C D are my correct answers
2
BBBBCCCCDDDD
B, C, E 2
Same as Linxek21 beside E instead of D, as automation is needed. E should work: https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/logging-using-cloudtrail.html#route-53-info-in-cloudtrail
2
Agree. The question asks to automate the process.
2
"If you use custom DNS domain names defined in a private hosted zone in Amazon Route 53, or use private DNS with interface VPC endpoints (AWS PrivateLink), you must set both the enableDnsHostnames and enableDnsSupport attributes to true." https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html
B, C, D 1
just BCD make sense.
1
This could work. Would take some testing to make sure your assigning to the Private Zone even though the event is based on the Public Zone.
1
I think the correct answers are BCD. Regarding the discussion about E. There is no requirement to do that automatically. If this is the case (but it's not stated in the Q), then E is required for automation process.
B, D, E 1
Not sure why others are going with option C. The question states that they are using custom dns records for external resolving and they want to use the same records for internal. > "Enable DNS hostnames for the application's VPC." This would not result in using the same records as external. > "Components of the application need to be able to access other components of the application within the application's VPC by using the same host names as the host names that are used over the public internet." Unless you are using the same hostnames of the EC2 instances for external resolving it doesn't make sense.
B, C, D 1
DNS Split View.. BCD are the correct answers.
1
I think that it's correcty answer is B & C & E.
1
While E approach might allow for some level of automation in updating DNS records, it's complex and involves CloudWatch Events and Lambda functions. Additionally, it doesn't address the core requirement of allowing components within the same VPC to access each other using the same hostnames.
1
Enabling DNS hostnames for the VPC is a prerequisite for using private hosted zones in Route 53. It ensures that instances within the VPC can resolve DNS queries using Route 53.
1
I think that it's correct answer is BCD according to SPOTO products.
1
There's big operation issue for E, unless you create another script to extract public hosted zone records and generate corresponding private zone records at the beginning. Otherwise, you have to keep running the app, potentially w/ errors each time, until all the private DNS names are populated.