A more granular way, would be to put these 3 paths into BindReadOnlyPaths, and wait for the creation of /etc/resolv.conf through a systemd.path unit.
BindReadOnlyPaths
/etc/resolv.conf
systemd.path