SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is migrating to a multi-account AWS environment. They want to centralize DNS management using Amazon Route 53 private hosted zones. The private zones must be accessible from all VPCs in the organization. Which THREE steps are required to achieve this?
⚠ Common exam trap
Many exam-takers confuse the need for a public hosted zone or outbound endpoints with the simpler mechanism of sharing a private hosted zone via AWS RAM and associating it with VPCs, leading them to select unnecessary or incorrect options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a private hosted zone in the central networking account.
Option A is correct because a Route 53 private hosted zone must first be created in the central networking (owner) account, which becomes the zone owner and controls its records and associations. Option B is correct because AWS Resource Access Manager (RAM) is the mechanism used to share the private hosted zone with other AWS accounts in the organization so their VPCs can be associated with it. Option D is correct because after sharing, the private hosted zone must be explicitly associated with each VPC in the member accounts (via AssociateVPCWithHostedZone or the console) for DNS resolution to work in those VPCs. Option C is wrong because a public hosted zone with DNSSEC does not provide private, internal resolution across VPCs and is unrelated to this requirement. Option E is wrong because a Route 53 Resolver outbound endpoint is used to forward DNS queries from a VPC to on-premises or external resolvers, not to share private hosted zones across accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a private hosted zone in the central networking account.
Why this is correct
A Route 53 private hosted zone must exist before any cross-account association can occur, so creating it in the central networking account establishes the single authoritative record container that member VPCs will later resolve against.
- ✓
Share the private hosted zone with other accounts using AWS Resource Access Manager.
Why this is correct
AWS RAM shares the private hosted zone with member accounts, granting them permission to associate it with their own VPCs. Without this share, association attempts from other accounts fail, since the zone belongs to the central networking account.
- ✗
Create a public hosted zone with the same name and configure DNSSEC.
Why it's wrong here
A public hosted zone resolves internet-facing names and DNSSEC signs public answers; neither makes a private zone reachable from other VPCs. It is tempting because DNSSEC and public zones are legitimate Route 53 features, but cross-VPC access requires associating the private hosted zone with each VPC.
- ✓
Associate the private hosted zone with the VPCs in the member accounts.
Why this is correct
Associating the private hosted zone with each member-account VPC is required because a Route 53 private hosted zone only resolves for VPCs explicitly associated with it, unless centralised through RAM or a shared-services hub. This satisfies the stem's constraint that the zone be accessible from all VPCs across the organisation.
- ✗
Create a Route 53 Resolver outbound endpoint in each account.
Why it's wrong here
An outbound endpoint forwards queries from your VPC to external DNS servers; it does not share a private hosted zone across accounts. It is tempting because Resolver endpoints are used for hybrid DNS, but the required step is associating the private hosted zone with the VPCs.
Visual reference
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.