Exam AZ-802 Topic 1 Question 208 Discussion
Actual exam question for Microsoft's AZ-802 exam
Question #: 208
Topic #: 1
Question #: 208
Topic #: 1
You have an on-premises DNS server named Server1 that runs Windows Server. Server1 hosts a DNS zone named fabrikam.com. You have an Azure subscription that contains the resources shown in the following exhibit: Vnet1 (virtual network, connects to the on-premises network by using a Site-to-Site VPN), VM1 (virtual machine, runs Windows Server and has the DNS Server role installed), contoso.com private DNS zone (linked to Vnet1), and contoso.com public DNS zone (contains the DNS records of all the platform as a service [PaaS] resources). How should you complete the name resolution configuration? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Vnet1 (Site-to-Site VPN) / VM1 (DNS Server role) / contoso.com private zone (linked to Vnet1) / contoso.com public zone (PaaS records).


Vnet1 (Site-to-Site VPN) / VM1 (DNS Server role) / contoso.com private zone (linked to Vnet1) / contoso.com public zone (PaaS records).

Suggested Answer:

Explanation:
On Vnet1 (VM1): configure VM1 to forward requests for the contoso.com zone to the Azure-provided DNS at 168.63.129.16. On the on-premises network: configure forwarding for the contoso.com zone to VM1.
The Azure-provided DNS resolver at 168.63.129.16 is what actually knows about the contoso.com private DNS zone, because that zone is linked to Vnet1 and platform DNS only answers private-zone queries for resources/clients located inside the linked virtual network; it cannot be queried directly by anything outside that VNet, including the on-premises network across the Site-to-Site VPN. VM1, however, sits inside Vnet1 and can reach 168.63.129.16 directly, so configuring VM1 ' s own DNS Server role to forward contoso.com queries to 168.63.129.16 lets VM1 successfully resolve private-zone records (and, transitively, records that depend on the public zone data for PaaS resources) on behalf of anyone who asks VM1. On the on-premises side, the on-premises DNS infrastructure has no direct path to the Azure platform resolver at all, so it must instead be configured to forward contoso.com queries to VM1 ' s IP address, which is reachable across the established Site-to-Site VPN. This produces a working chain: on-premises clients query their local DNS server, which forwards contoso.com queries across the VPN to VM1, which in turn forwards them to the Azure-provided DNS resolver that can actually see the linked private zone, and the resolved answer flows back along the same path. Configuring VM1 to forward to the public DNS zone directly, or configuring on- premises forwarding straight to 168.63.129.16 or to the public zone, would each skip a required hop and fail to resolve the private zone ' s records.
by Teresa at Oct 05, 2026, 04:28 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).