Soru

Zorluk: OrtaMulti-Account and Hybrid DNS Architecture Strategy

A biotechnology research corporation is migrating its workflows to AWS using AWS Organizations. The central network topology consists of a Network Services VPC hosted in a shared infrastructure account, connected to several Research and Development (R&D) VPCs in different member accounts via an AWS Transit Gateway. The on-premises data center connects to the Transit Gateway via an AWS Direct Connect gateway connection. A Route 53 Private Hosted Zone (PHZ) for aws.biotech.internal is created in the Network Services account and associated with the Network Services VPC. The R&D VPCs must be able to resolve domain names inside aws.biotech.internal. Additionally, all R&D VPCs must resolve on-premises domain names in the corp.biotech.internal namespace. Which TWO configurations must a Solutions Architect implement to achieve this DNS resolution strategy? (Select TWO.)

  1. Authorize the association of the aws.biotech.internal Private Hosted Zone with the R&D VPCs from the Network Services account, and then associate the R&D VPCs with the hosted zone from each member account.Cevap
  2. Create a Route 53 Resolver outbound endpoint in the Network Services VPC, configure an outbound forwarding rule for corp.biotech.internal pointing to the on-premises DNS servers, share this rule with the organization using AWS Resource Access Manager (RAM), and associate the rule with the R&D VPCs.Cevap
  3. C
    Share the aws.biotech.internal Private Hosted Zone directly with the R&D member accounts using AWS Resource Access Manager (RAM), and then associate the shared hosted zone with the R&D VPCs in the member accounts.
  4. D
    Create a Route 53 Resolver outbound endpoint in each R&D VPC, and configure the R&D VPC route tables to route DNS queries (port 53) directly to the Direct Connect Gateway attachment to bypass the Transit Gateway.
  5. E
    Create a Route 53 Resolver inbound endpoint in the Network Services VPC, configure a wildcard forwarding rule for biotech.internal in the R&D member accounts, and configure the R&D VPC route tables to forward all DNS queries directly to the inbound endpoint's IP addresses.

Cevap

To establish hybrid and cross-account DNS resolution, the Solutions Architect must authorize and associate the private hosted zone cross-account, and configure a Route 53 Resolver outbound endpoint with a shared forwarding rule.
The correct options implement a standard hybrid DNS pattern. Cross-account Private Hosted Zones are associated using Route 53 VPC association authorization, and on-premises resolution is achieved by using a centralized outbound Route 53 Resolver endpoint and sharing the resolver forwarding rules across the AWS Organization using AWS Resource Access Manager (RAM).

Adım Adım Çözüm

1
Authorize cross-account association of the Private Hosted Zone.
The Network Services account creates an association authorization for each R&D VPC.
This allows the member accounts to associate their VPCs with a Private Hosted Zone owned by a different account.
2
Associate the R&D VPCs with the Private Hosted Zone.
Each R&D VPC is associated with the aws.biotech.internal hosted zone.
This enables DNS resolution of internal AWS resources directly within the spoke VPCs.
3
Set up centralized Route 53 Resolver outbound endpoints and rules.
An outbound endpoint is created in the central VPC, and a forwarding rule for the on-premises namespace is shared via AWS RAM.
This routes all DNS queries for the on-premises domain from R&D VPCs through the Transit Gateway to the on-premises DNS servers.

Anahtar Kavram

Cross-account Private Hosted Zone sharing and hybrid name resolution using Route 53 Resolver outbound endpoints and AWS RAM.
Bu soruyu puanla