Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company is using Amazon Route 53 with a private hosted zone for internal DNS resolution within a VPC. The VPC is connected to an on-premises network via a VPN. On-premises resources cannot resolve DNS names in the private hosted zone. Which TWO actions should be taken to resolve this issue? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable DNS resolution and DNS hostnames for the VPC.

To allow on-premises resources to resolve DNS names in a private hosted zone, you need to create a Route 53 inbound resolver endpoint in the VPC (option E). This endpoint allows DNS queries from on-premises to be forwarded to Route 53. Additionally, you must enable DNS resolution and DNS hostnames for the VPC (option C) to ensure that the VPC's DNS settings support internal resolution. Option A is incorrect because route propagation affects network routing, not DNS resolution. Option B is incorrect because private hosted zones cannot be associated with on-premises networks directly. Option D is incorrect because a public hosted zone is used for public DNS and does not resolve private DNS queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure route propagation from the VPN to the VPC's route table.

    Why it's wrong here

    Route propagation in the VPC route table is a BGP-based mechanism for learning network routes from the VPN connection, not a DNS service. Adding propagated routes tells VPC routers how to send traffic to on-premises CIDRs, but it does not configure Route 53 to answer DNS queries on behalf of the on-premises network. VPC DNS resolution is governed by the VPC's DNS settings and Route 53 Resolver endpoints, not by route table advertisements.

  • ✗

    Associate the private hosted zone with the on-premises network.

    Why it's wrong here

    A private hosted zone can be associated only with VPCs, using either a same-account association or an authorized cross-account VPC association. The on-premises network is not a VPC, so the association API will not accept it, and the zone has no ability to service DNS queries from outside the VPC(s) to which it is linked. To provide resolution for on-premises clients, you must expose the private zone through a Route 53 inbound resolver endpoint in the associated VPC.

  • ✓

    Enable DNS resolution and DNS hostnames for the VPC.

    Why this is correct

    This is a required VPC setting: the VPC must have both DNS resolution (the Amazon-provided DNS server at the VPC CIDR + 2) and DNS hostnames enabled. When DNS resolution is enabled, Route 53 can answer queries against private hosted zones from instances or the VPC resolver; DNS hostnames is necessary for AWS to assign and use internal DNS names for instances. Without these settings, the VPC's resolver behavior is disabled and private-hosted-zone lookups fail.

  • ✗

    Create a public hosted zone with the same name and associate it with the VPC.

    Why it's wrong here

    A public hosted zone is an internet-facing DNS namespace intended for routing traffic from resolvers outside AWS, and it cannot be 'associated with a VPC' in the way private hosted zones can. The association operation is only valid for private hosted zones, and a public hosted zone requires public DNS delegation via name servers, not a VPC attachment. Creating a public zone with the same name would not help private resolution and could actually confuse hybrid DNS routing.

  • ✓

    Create a Route 53 inbound resolver endpoint in the VPC.

    Why this is correct

    A Route 53 inbound resolver endpoint provisions elastic network interfaces in the VPC with dedicated IP addresses that on-premises DNS resolvers can forward queries to via conditional forwarding. This endpoint accepts DNS traffic from the on-premises network and forwards it to the Route 53 private hosted zone's resolver, making hybrid name resolution possible. The endpoint is the missing piece for non-VPC clients to reach the private hosted zone without changing the zone's VPC association.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.