Topic 1 Question 103
Your organization uses a hub-and-spoke architecture with critical Compute Engine instances in your Virtual Private Clouds (VPCs). You are responsible for the design of Cloud DNS in Google Cloud. You need to be able to resolve Cloud DNS private zones from your on-premises data center and enable on-premises name resolution from your hub-and-spoke VPC design. What should you do?
- Configure a private DNS zone in the hub VPC, and configure DNS forwarding to the on-premises server.
- Configure DNS peering from the spoke VPCs to the hub VPC.
- Configure a DNS policy in the hub VPC to allow inbound query forwarding from the spoke VPCs.
- Configure the spoke VPCs with a private zone, and set up DNS peering to the hub VPC.
- Configure a DNS policy in the spoke VPCs, and configure your on-premises DNS as an alternate DNS server.
- Configure the hub VPC with a private zone, and set up DNS peering to each of the spoke VPCs.
- Configure a DNS policy in the hub VPC, and configure the on-premises DNS as an alternate DNS server.
- Configure the spoke VPCs with a private zone, and set up DNS peering to the hub VPC.
ユーザの投票
コメント(6)
- 正解だと思う選択肢: A
I go with A. In my opinion C and D are wrong (on-premises DNS as an alternate DNS server?) B is also wrong: configure a DNS policy in the HUB VPC to allow inbound query forwarding from the spoke VPC. This is not needed " DNS peering runs in parallel with VPC Network Peering connections to allow name resolution between environments." A is correct, although is missing second part of requirements in the question (resolution from on-prem to Google Cloud). https://cloud.google.com/dns/docs/best-practices#hybrid-architecture-using-hub-vpc-network-connected-to-spoke-vpc-networks
👍 5al_zo2022/12/05 - 正解だと思う選択肢: B
C and D for me is wrong, no make sense DNS on premise like alternative. A is wrong, because inverted direction is necessary onpremise > cloud dns.
B is next to solution, but one step is necessary to, and there isn't mention to DNS policy to allow DNS condicional forwarding from on premise.
I'll go to B.
👍 4ccieman20162022/12/01 B could be right but how does outgoing traffic from GC to on-orem work
👍 4playpacman2022/12/01
シャッフル モード