Enable private DNS on the VPC so interface endpoint hostnames resolve to private addresses

Answer Correct answer: B — Enable the private DNS option in the VPC attributes so the service names resolve to the interface endpoints' private addresses.

A company requires that all internal application connectivity use private IP addresses. To facilitate this policy, a solutions architect has created interface endpoints to connect to AWS Public services. Upon testing, the solutions architect notices that the service names are resolving to public IP addresses, and that internal services cannot connect to the interface endpoints. Which step should the solutions architect take to resolve this issue?

  1. Update the subnet route table with a route to the interface endpoint.
  2. Enable the private DNS option on the VPC attributes. Correct Answer
  3. Configure the security group on the interface endpoint to allow connectivity to the AWS services.
  4. Configure an Amazon Route 53 private hosted zone with a conditional forwarder for the internal application.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Interface endpoints only receive private DNS names when the enableDnsSupport and enableDnsHostnames properties are turned on for the VPC and the private DNS option is enabled for the specific endpoint, which is a VPC attributes setting rather than a routing setting.

A policy requires all internal application connectivity to use private IP addresses, so interface endpoints were created for AWS public services. Testing shows the service names still resolve to public IP addresses and internal services cannot reach the endpoints.

Adding a route to the interface endpoint or editing its security group. Those settings matter for reachability once name resolution is correct, but here the names are resolving to public addresses, so the failure is at the DNS layer and the security group would be evaluated only after traffic is aimed at the endpoint's private addresses.

Community Discussion (8 comments)

ebbff63 👍 6 Selected: B
ensures proper DNS resolution for VPC endpoints.
AzureDP900 👍 1
By choosing option B, the solutions architect can enable private DNS on the VPC attributes, which will resolve service names to private IP addresses, allowing internal applications to connect to interface endpoints without issues.
0b43291 👍 3 Selected: B
The correct step the solutions architect should take to resolve the issue of service names resolving to public IP addresses and internal services not being able to connect to the interface endpoints is Option B: Enable the private DNS option on the VPC attributes. When you create an interface endpoint, AWS automatically creates a private DNS name for the service that resolves to the private IP addresses of the interface endpoint. However, by default, the private DNS option is disabled on the VPC, which means that DNS queries for the service name will be resolved using the public DNS instead of the private DNS provided by the interface endpoint. By enabling the private DNS option on the VPC attributes, you instruct the VPC to use the private DNS names provided by the interface endpoints for the specified AWS services. This ensures that the service names resolve to the private IP addresses of the interface endpoints, allowing internal services within the VPC to connect to the AWS services using private IP addresses, as per the company's policy.
chris_spencer 👍 1 Selected: B
B .. .because we had exact this problem once. C would be right if name would be resolved to a private IP, but as described it is not, it resolves to the public ip, so B
backbencher2022 👍 1 Selected: B
Sorry, Ignore my previous comment. private DNS would solve the issue. Option B is correct
backbencher2022 👍 1 Selected: C
C (security group) is correct. Private DNS resolution is neither a mandatory pre-requisite to use interface endpoints nor a requirement in this question. If you read the question again, resolving to a public IP is a distractor which makes us think that private DNS (option B) is the correct option. The real problem is the 2nd issue of the question - not able to connect which is a security group configuration issue. Even if you don't want to use private DNS, your interface endpoint will still work however, without security group rule configured, you can't use interface endpoint at all. Check this document for a list of pre-requisites - https://docs.aws.amazon.com/vpc/latest/privatelink/create-interface-endpoint.html and 2nd point says "To use private DNS..." which implies you may or may not want to use Private DNS however, 4th pre-requisite "Create a security group...." is mandatory.
dzidis 👍 1
Here in prerequisites for interface endpoint: To use private DNS, you must enable DNS hostnames and DNS resolution for your VPC. For more information, see View and update DNS attributes in the Amazon VPC User Guide. https://docs.aws.amazon.com/vpc/latest/privatelink/create-interface-endpoint.html
mifune 👍 1 Selected: B
Private DNS for Interface Endpoints. Answer B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When private DNS is enabled for a VPC and for the interface endpoint, the standard AWS service hostname resolves to the endpoint's private IP addresses through Amazon-provided private hosted zones. Enabling the private DNS option in the VPC attributes is therefore the step that makes the service names resolve to private addresses instead of their public endpoints, and it is what allows the internal services to connect to the interface endpoints at all.

Why the Other Options Are Wrong

A: A route in the subnet route table directs traffic destined for the endpoint's private addresses, but the clients are not sending traffic to those addresses because name resolution returns public ones, so the route never matches. C: The security group on the endpoint governs which traffic is accepted once it arrives, which also requires correct name resolution first. D: A Route 53 private hosted zone with a conditional forwarder is a mechanism for resolving internal names to on-premises locations, not for steering AWS service names to interface endpoints.

Community Comment Notes

The community voted 92 to 1 for B. The key clarification came from a commenter who noted that option C would be relevant if the names were already resolving to private addresses, but since the observed symptom is resolution to public addresses, the DNS setting is the correct fix.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide