ANS-C01 exam dumps

ANS-C01 practice question 305 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 305

Select 2

Your organization has separate AWS accounts for different business units. The central IT team manages a Route 53 private hosted zone in their account, and the business units need to resolve domain names from this hosted zone in their respective Amazon VPCs. How can you enable this DNS sharing securely and efficiently across accounts?

  1. A

    Use AWS Resource Access Manager (RAM) to share the Route 53 private hosted zone with the other accounts and associate it with their VPCs.

  2. B

    Create a new Route 53 public hosted zone for each account and replicate the DNS records from the private hosted zone.

  3. C

    Share the Route 53 private hosted zone using AWS RAM and ensure the VPCs in the other accounts have appropriate association authorization.

  4. D

    Manually create identical private hosted zones in each of the accounts and add the same DNS records to each zone.

  5. E

    Establish a centralized DNS forwarding solution using Amazon Route 53 Resolver and share resolver rules with other accounts.

Show answer and explanation

Correct answers: A, C

Explanation

To share DNS services between accounts, AWS RAM is the recommended approach for securely sharing Route 53 private hosted zones. By sharing the private hosted zone and associating it with the VPCs in the other accounts, you enable seamless DNS resolution across accounts without duplicating DNS configurations. Additionally, VPC association authorization ensures security and proper access control.

  • A. Correct.

    Correct: AWS RAM allows you to share Route 53 private hosted zones securely across accounts. You can then associate the shared zone with the VPCs in the other accounts.

  • B. Incorrect.

    Incorrect: Public hosted zones are used for DNS resolution over the internet and cannot be used for private DNS resolution within VPCs.

  • C. Correct.

    Correct: Sharing the private hosted zone using AWS RAM requires ensuring that VPCs in other accounts are authorized for association. This step is critical for secure and functional cross-account DNS sharing.

  • D. Incorrect.

    Incorrect: Manually creating identical private hosted zones in each account is inefficient and prone to errors. Additionally, this does not provide an automated or scalable solution.

  • E. Incorrect.

    Incorrect: While Route 53 Resolver forwarding rules can centralize DNS forwarding, they are not required to share Route 53 private hosted zones and would be an overcomplication for this use case.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam