Network and Content Delivery
CoreAmazon Route 53 Resolver DNS Firewall
Explicit network-protection audit example.
Key points
- Resolver DNS Firewall applies DNS-query controls at its configured VPC association and rule scope.
Best-known use cases
- D2.1, D2.2, and D5.1: audit or troubleshoot a named DNS-query protection rule and its associations.
What candidates often confuse it with
- DNS Firewall filters DNS queries; AWS WAF filters supported web requests and Network Firewall filters VPC traffic.
Key takeaway
Choose DNS Firewall only for the name-resolution layer and verify rule action, priority, association, and logs.
Related services
- Amazon Application Recovery Controller
- AWS Client VPN
- Amazon CloudFront
Relevant exam tasks
- D2.1 — Task 2.1: Implement scalability and elasticity.
- 2.1.1 — Configure and manage scaling mechanisms in compute environments.
- D2.2 — Task 2.2: Implement highly available and resilient environments.
- 2.2.1 — Configure and troubleshoot Elastic Load Balancing (ELB) and Amazon Route 53 health checks.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).