Northwind has an ExpressRoute circuit to a hub virtual network. On-premises servers must resolve privatelink.blob.core.windows.net records that are held in an Azure private DNS zone, and the design must avoid running and patching DNS forwarder virtual machines. You need to enable the resolution. What should you deploy in the hub virtual network?
- A.
A public Azure DNS zone named blob.core.windows.net that contains the private endpoint A records
- B.
Configure a conditional forwarder for blob.core.windows.net on the on-premises DNS servers that targets 168.63.129.16, and advertise 168.63.129.16/32 to on-premises over the ExpressRoute circuit
- C.
An Azure DNS Private Resolver with an inbound endpoint, then point an on-premises conditional forwarder for blob.core.windows.net at the inbound endpoint IP address
- D.
An Azure DNS Private Resolver with an outbound endpoint and a DNS forwarding ruleset for blob.core.windows.net
Show answer
Answer: C
An inbound endpoint on Azure DNS Private Resolver gives on-premises resolvers a private IP address in the VNet to forward Azure private zone queries to.
- A. A public DNS zone cannot hold private endpoint resolution for the Microsoft-owned blob namespace and would not be authoritative for on-premises clients anyway.
- B. 168.63.129.16 is only reachable from inside a virtual network, so an on-premises forwarder aimed at it cannot receive answers.
- C. The inbound endpoint provides a VNet private IP that on-premises resolvers can forward to, and it answers from every private DNS zone linked to that virtual network.
- D. Outbound endpoints and forwarding rulesets send queries from Azure toward on-premises DNS, which is the reverse of the required direction.
