AWS SAP-C02 · Question 56 · Domain 1.1: Network Connectivity
An architect is designing a secure VPC architecture. The VPC contains private subnets with EC2 instances that need to download software patches from Amazon S3 and access Amazon DynamoDB. The instances must NOT have internet access. Which TWO solutions provide the MOST secure and cost-effective connectivity? (Select TWO)
An architect is designing a secure VPC architecture. The VPC contains private subnets with EC2 instances that need to download software patches from Amazon S3 and access Amazon DynamoDB. The instances must NOT have internet access. Which TWO solutions provide the MOST secure and cost-effective connectivity? (Select TWO)
Answer options:
Create a Gateway VPC Endpoint for Amazon S3.
Create an Interface VPC Endpoint (AWS PrivateLink) for Amazon S3.
Create a Gateway VPC Endpoint for Amazon DynamoDB.
Deploy a NAT Gateway in a public subnet.
Configure an AWS VPN connection to the AWS public zone.
Use AWS Transit Gateway to route traffic to the public internet.
How to approach this question
Full Answer
Common mistakes
Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1
75 questions · hints · full answers · grading
Expert