Azure DNS Private Resolver Minimum Deployment
You have an on-premises DNS server named Server that hosts a primary DNS zone named fabrikam.com. You have an Azure subscription that contains the resources shown in the following table. Users on the on-premises network access resources on all the virtual networks by using a Site-to-Site (S2S) VPN. You need to deploy an Azure DNS Private Resolver solution that meets the following requirements: • Resources connected to the virtual networks must be able to resolve DNS names for fabrikam.com. • Server1 must be able to resolve the DNS names of the resources in contoso.com. • The solution must minimize costs and administrative effort. What is the minimum number of resolvers you should deploy? - 
Community Votes
62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core trap is assuming a single global resolver can handle all queries; in reality, resolvers are regional services that must reside in the same region as the VNets they resolve or query.
This question addresses the regional constraints of Azure DNS Private Resolvers and determines the minimum deployment required to facilitate bidirectional name resolution between on-premises and multi-region Azure environments.
Candidates often select '1' (Option A), mistakenly believing that a Private DNS Zone's global scope allows a single resolver in one region to service VNets in other regions via S2S VPN.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B (2). Azure DNS Private Resolver is a regional resource, meaning an inbound or outbound endpoint must be located in the same Azure region as the virtual network it connects to. To satisfy the requirements, you need at least two resolvers: one in Region 1 to allow on-premises users to resolve fabrikam.com (via an Outbound Endpoint linked to VNet1) and one in Region 2 to allow Server1 to resolve contoso.com resources (via an Inbound Endpoint linked to VNet2). While technically a single resolver could be used if both VNets were peered to it, the requirement for Server1 to resolve resources implies a need for connectivity from the on-premises side which typically necessitates specific endpoint placement per region to minimize latency and administrative overhead across the disconnected VNets.Why the Other Options Are Wrong
Option A (1) is incorrect because a single resolver cannot natively serve as an Inbound Endpoint for one region and an Outbound Endpoint for another if those VNets are not connected to that specific resolver's region. Since the VNets are distinct and likely in different regions (implied by the need for separate resolution paths), deploying only one would fail to meet the requirement for Server1 to resolve Azure resources unless complex cross-region routing was established, which violates the 'minimize effort' constraint. Options C (3) and D (4) represent unnecessary deployments that increase cost without adding functional value for this specific topology.Community Comment Notes
Community consensus leans towards B, with several users citing the regional limitation documentation. As Gambito11 noted, "A DNS resolver can only refer to a virtual network that's in the same region as the DNS resolver." This confirms that you need a resolver instance in each relevant region to bridge the gap between on-premises and Azure resources effectively.Official Reference
Exam Strategy
Always check the regionality of Azure networking components. If a component is regional, count the number of regions involved in the solution to determine the minimum number of instances required.
Frequently Asked Questions
Can one Azure DNS Private Resolver serve multiple regions?
No, resolvers are regional. You must deploy at least one resolver per region where you need to connect VNets or provide endpoints.
Why not use just 1 resolver for fabrikam.com resolution?
While 1 resolver might suffice for one direction, the requirement for Server1 to resolve Azure names requires an inbound endpoint in the Azure region, necessitating a second resolver or complex peering.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →