Skip to content
BytePatterns

SOA-C03 · Domain 5: Networking and Content Delivery · 18% of the exam

Task 5.2: Configure domains, DNS services, and content delivery.

Names and edges: Route 53 hosted zones, routing policies, Resolver and query logging, and delivering content and traffic through CloudFront and Global Accelerator.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A company runs version 1 of an API behind a load balancer and has deployed version 2 behind a second load balancer in the same AWS Region. Both are reached through api.example.com in Amazon Route 53. The team wants to send about 10% of requests to version 2, watch its error rate, and then raise the share step by step. Which routing policy should the team use?

  1. ALatency-based routing, with one record for each load balancer
  2. BWeighted routing, with weights of 90 and 10 on the records
  3. CGeolocation routing, sending one country's users to version 2
  4. DFailover routing, with version 2 as the secondary record
Show the answer and why
  • ALatency-based routing, with one record for each load balancer

    Incorrect

    Latency routing picks the Region with the lowest latency for the user. Both stacks are in one Region, so it cannot split traffic by share.

  • BWeighted routing, with weights of 90 and 10 on the records

    Correct

    Weighted routing sends traffic to each record in proportion to its weight, which AWS describes for testing new versions of software.

  • CGeolocation routing, sending one country's users to version 2

    Incorrect

    Geolocation routes by where users are. The share of traffic would depend on the chosen location, not on a percentage the team sets.

  • DFailover routing, with version 2 as the secondary record

    Incorrect

    Failover routing sends traffic to the secondary only when the primary is unhealthy, so version 2 would get no traffic in normal operation.

Canary releases at the DNS level use weighted records: change the weights to shift the share without touching the clients.

Question 2 · choose 1

A VPC is connected to a corporate data center through AWS Site-to-Site VPN. Records for corp.internal live in an Amazon Route 53 private hosted zone that is associated with the VPC. Servers in the data center must resolve those names, and the data center's DNS servers can forward queries for a domain to any IP address the team gives them. What should the team set up?

  1. AA Resolver outbound endpoint with a forwarding rule for corp.internal
  2. BAn association between the private hosted zone and the data center network
  3. CA Resolver inbound endpoint, with corp.internal forwarded to it
  4. DA DNS Firewall rule group that allows corp.internal, associated with the VPC
Show the answer and why
  • AA Resolver outbound endpoint with a forwarding rule for corp.internal

    Incorrect

    An outbound endpoint forwards queries that start in the VPC to the corporate network, the opposite direction.

  • BAn association between the private hosted zone and the data center network

    Incorrect

    A private hosted zone answers queries within the VPCs that are associated with it; it cannot be associated with an on-premises network.

  • CA Resolver inbound endpoint, with corp.internal forwarded to it

    Correct

    An inbound endpoint gives the VPC's resolver private IP addresses that resolvers on the corporate network can forward queries to over the VPN.

  • DA DNS Firewall rule group that allows corp.internal, associated with the VPC

    Incorrect

    DNS Firewall filters outbound DNS queries from the VPC. It does not let outside servers send queries in.

Queries coming into AWS use an inbound endpoint; queries leaving AWS use an outbound endpoint with forwarding rules.

Question 3 · choose 1

A team must record the name and type of every DNS query that Amazon Route 53 answers for the public hosted zone example.com. All of the team's workloads and CloudWatch Logs log groups are in eu-west-1, and an attempt to set up query logging for the zone with a log group in eu-west-1 does not work. What should the team do?

  1. AUse a log group in US East (N. Virginia) for the zone's query logging
  2. BTurn on Resolver query logging for every VPC that the team runs in eu-west-1
  3. CTurn on VPC flow logs for the subnets in eu-west-1
  4. DRead the hosted zone's CloudWatch DNS query metrics instead of logs
Show the answer and why
  • AUse a log group in US East (N. Virginia) for the zone's query logging

    Correct

    For public DNS query logging, Route 53 publishes to a CloudWatch Logs log group that must be in the US East (N. Virginia) Region.

  • BTurn on Resolver query logging for every VPC that the team runs in eu-west-1

    Incorrect

    Resolver query logging records queries that originate in the chosen VPCs or pass through Resolver endpoints, not queries from resolvers on the internet for a public zone.

  • CTurn on VPC flow logs for the subnets in eu-west-1

    Incorrect

    Flow logs capture information about IP traffic to and from network interfaces, not the DNS queries Route 53 answers for the zone.

  • DRead the hosted zone's CloudWatch DNS query metrics instead of logs

    Incorrect

    The metrics show the total number of queries. They do not record the name and type of each query.

Public DNS query logs always go to a log group in us-east-1, whatever Region the workloads use.

Question 4 · choose 2

A CloudFront distribution serves images from an Amazon S3 bucket. Today the bucket policy allows public read access, so users can bypass CloudFront and download the images straight from the bucket's S3 URL. The operations team wants the objects to be readable only through this distribution. Which actions should the team take? (Choose TWO.)

  1. ARequire CloudFront signed URLs for every request to the distribution
  2. BCreate an origin access control and attach it to the distribution's S3 origin
  3. CAssociate an AWS WAF web ACL with the S3 bucket to block requests that do not come from CloudFront
  4. DGive users presigned URLs for the objects instead of the bucket URLs
  5. EReplace the bucket policy with one that allows only cloudfront.amazonaws.com, conditioned on the distribution ARN
Show the answer and why
  • ARequire CloudFront signed URLs for every request to the distribution

    Incorrect

    Signed URLs restrict who can use the CloudFront URLs. AWS separately recommends stopping direct access to the origin, which signed URLs do not do.

  • BCreate an origin access control and attach it to the distribution's S3 origin

    Correct

    With origin access control, CloudFront sends authenticated requests to the S3 origin, and AWS recommends OAC over the older origin access identity.

  • CAssociate an AWS WAF web ACL with the S3 bucket to block requests that do not come from CloudFront

    Incorrect

    S3 buckets are not among the resource types that AWS WAF can protect, such as CloudFront distributions and Application Load Balancers.

  • DGive users presigned URLs for the objects instead of the bucket URLs

    Incorrect

    A presigned URL grants time-limited access to S3 directly. It neither routes users through CloudFront nor removes public access.

  • EReplace the bucket policy with one that allows only cloudfront.amazonaws.com, conditioned on the distribution ARN

    Correct

    The bucket policy should allow the CloudFront service principal only when AWS:SourceArn is the distribution that contains the S3 origin; with the public statement gone, direct reads fail.

Locking an S3 origin to one distribution takes both halves: OAC so that CloudFront signs its requests, and a bucket policy that trusts only that distribution.

Practise domain 5 →Practise all domains →