SOA-C02 Networking and Content Delivery Practice Question
A company has a VPC that requires DNS resolution for custom domain names within the VPC. They want to use a private hosted zone in Amazon Route 53. Which resource is required to associate the private hosted zone with the VPC?
⚠ Common exam trap
It's easy for candidates to confuse the resource needed for association (the VPC) with DNS record types or resolver configurations, mistakenly thinking a CNAME record or resolver rule is required to link the hosted zone to the VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A VPC
To associate a private hosted zone with a VPC in Amazon Route 53, you must specify the VPC ID and the AWS Region of the VPC. The VPC itself is the required resource because the private hosted zone is scoped to one or more VPCs, enabling DNS resolution for custom domain names only within those VPCs. Without a VPC association, the private hosted zone cannot serve DNS queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A resolver rule
Why it's wrong here
A resolver rule is a Route 53 Resolver configuration that defines how DNS queries for specific domain names are forwarded to target IP addresses, such as an on-premises DNS server. It is used to manage hybrid DNS resolution between VPCs and on-premises networks, not to associate a hosted zone with a VPC. A private hosted zone must be directly linked to a VPC using the association API or console action, so a resolver rule does not satisfy this requirement.
- ✗
A public hosted zone
Why it's wrong here
A public hosted zone is a DNS namespace that Route 53 serves from the public internet, with records visible to anyone. A private hosted zone is an internal namespace that is only accessible inside VPCs, and the two types are completely independent at the zone level. Creating or associating a private hosted zone does not require any public zone, and the association is specifically between the private zone and a VPC, not between two hosted zones.
- ✓
A VPC
Why this is correct
A private hosted zone must be associated with one or more Amazon VPCs before resources inside those VPCs can resolve the zone's records. Without this explicit association, the zone remains created but unusable, even if instances are in the same AWS account. Route 53 merges the private hosted zone's records with the default VPC DNS only after the association request succeeds, which makes the VPC the required target resource.
- ✗
A CNAME record
Why it's wrong here
A CNAME record is a DNS record type that maps a hostname alias to another canonical name, typically added within a hosted zone to support aliasing. It does not perform any network-level linking and cannot be used to associate a hosted zone with a VPC. The association requirement is for the hosted zone as a whole, not for individual record sets; therefore, adding a CNAME record does not make a private hosted zone available.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.