AWS Certified Advanced Networking – Specialty ANS-C00 – Question288

You have a hybrid environment in which your VPC queries your on-premises DNS server for up resources in your environment. The EC2 instances in your VPC are unable to resolve on-premises resources.
What are two possible reasons for this problem? (Choose two.)

A.
Your NACL is blocking UDP port 53 outbound
B. Your security group is blocking port 53 inbound
C. Your NACL is blocking TCP port 53 outbound.
D. Your on-premises firewall is blocking port 443

Correct Answer: AC

Explanation:

Explanation:
DNS requires TCP and UDP port 53.