Hard1 markMultiple Choice

AWS SAP-C02 · Question 15 · Domain 1.4: Multi-Account Environment

A company is setting up a shared services VPC. They want to allow other VPCs in their AWS Organization to resolve internal DNS names hosted in Amazon Route 53 Private Hosted Zones within the shared services VPC. Which TWO steps are required? (Select TWO)

Answer options:

A.

Create a Route 53 Public Hosted Zone and restrict access via IAM.

B.

Associate the Private Hosted Zone with the spoke VPCs using the Route 53 API/CLI.

C.

Deploy an AWS Directory Service for Microsoft Active Directory.

D.

Ensure VPC Peering or Transit Gateway connectivity exists between the spoke VPCs and the shared services VPC.

E.

Configure Route 53 Resolver Outbound Endpoints in the spoke VPCs.

F.

Use AWS RAM to share the Route 53 Private Hosted Zone.

How to approach this question

Identify how Private Hosted Zones are shared across VPCs.

Full Answer

B,D
To share a Private Hosted Zone across accounts, you must programmatically associate the PHZ with the spoke VPCs. You also need network connectivity (TGW/Peering) to actually route traffic to the resolved IPs.

Common mistakes

Assuming AWS RAM can share PHZs natively.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 2

75 questions · hints · full answers · grading

More questions from this exam