A junior administrator needs to verify that the host can resolve the name db.internal.example.com to an IPv4 address before deploying a database client. The system uses systemd-resolved. Which command queries the configured resolver and displays the answer without relying on the local nsswitch.conf ordering?
resolvectl query sends the name to systemd-resolved and reports the answer along with which link and DNS server provided it. This directly exercises the resolver configured on the system, bypassing nsswitch.conf ordering, and is the correct tool on systemd-resolved hosts. It also shows whether the answer came from cache, DNS, or another source, which is valuable for troubleshooting.
Why this answer
resolvectl query is the native client for systemd-resolved. It sends the query through the resolver daemon, showing the answer, the link used, and the DNS server that responded. This isolates DNS resolution from nsswitch.conf sources like /etc/hosts, which is exactly what is needed to confirm the configured resolver can resolve the name.
Exam trap
The trap here is assuming that any lookup tool tests the configured resolver, when tools like getent and host actually follow nsswitch.conf and may return /etc/hosts entries instead.