QuestionQ19

Design Solutions for Organizational Complexity

A company uses multiple AWS accounts. DNS records are kept in an Amazon Route 53 private hosted zone in Account A, while the company's applications and databases run in Account B.

A solutions architect will deploy a two-tier application into a new VPC. To simplify configuration, a db.example.com CNAME record set for the Amazon RDS endpoint was created in an Amazon Route 53 private hosted zone.

During deployment, the application did not start. Troubleshooting showed that db.example.com cannot be resolved from the Amazon EC2 instance. The solutions architect verified that the record set was correctly created in Route 53.

Which combination of steps should the solutions architect take to resolve this issue?

Choose two
Explanation

A Route 53 private hosted zone can resolve its records from a VPC only when that VPC is associated with the hosted zone. For a cross-account association, the account that owns the hosted zone must first create an association authorization, and the account that owns the VPC must associate the VPC with that hosted zone. The authorization can then be deleted without affecting the existing association.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!