nerdexam
Microsoft

AZ-800 · Question #289

You have an on-premises server named DNS1 that runs Windows Server and has the DNS Server role. You have an Azure subscription that contains an Azure Private DNS zone named contoso.com. You…

The correct answer is D. a secondary DNS zone. To allow DNS1 to resolve names from the Azure Private DNS zone contoso.com via Resolver1, you configure a secondary DNS zone for contoso.com on DNS1. DNS1 acts as a secondary server that can receive and serve zone data, forwarding unresolvable queries toward Resolver1's inbound…

Implement and manage an on-premises and hybrid networking infrastructure

Question

You have an on-premises server named DNS1 that runs Windows Server and has the DNS Server role. You have an Azure subscription that contains an Azure Private DNS zone named contoso.com. You implement an Azure DNS Private Resolver named Resolver1. You need to ensure that DNS1 can resolve names from contoso.com by using Resolver1. The solution must minimize administrative effort. What should you configure?

Exhibit

AZ-800 question #289 exhibit

Options

  • ADNS policy
  • Ba Site-to-Site (S2S) VPN connection
  • Croot hints
  • Da secondary DNS zone

How the community answered

(20 responses)
  • A
    10% (2)
  • B
    5% (1)
  • C
    5% (1)
  • D
    80% (16)

Explanation

To allow DNS1 to resolve names from the Azure Private DNS zone contoso.com via Resolver1, you configure a secondary DNS zone for contoso.com on DNS1. DNS1 acts as a secondary server that can receive and serve zone data, forwarding unresolvable queries toward Resolver1's inbound endpoint, enabling resolution of the private Azure zone. A DNS policy (Option A) controls query behavior on a per-policy basis but does not directly enable zone resolution via Resolver1 with minimal effort. Root hints (Option C) point to global root DNS servers and are irrelevant here. A Site-to-Site VPN (Option B) provides network connectivity but is a prerequisite infrastructure component, not a DNS configuration - and the question implies connectivity is already in place since Resolver1 is implemented.

Topics

#DNS#Hybrid DNS#Azure Private DNS#DNS Private Resolver

Community Discussion

No community discussion yet for this question.

Full AZ-800 Practice