Easy1 markMultiple Choice
Domain 1.1: Network ConnectivityNetworkingSecurityVPC Endpoints

AWS SAP-C02 · Question 56 · Domain 1.1: Network Connectivity

An architect is designing a secure VPC architecture. The VPC contains private subnets with EC2 instances that need to download software patches from Amazon S3 and access Amazon DynamoDB. The instances must NOT have internet access. Which TWO solutions provide the MOST secure and cost-effective connectivity? (Select TWO)

Answer options:

A.

Create a Gateway VPC Endpoint for Amazon S3.

B.

Create an Interface VPC Endpoint (AWS PrivateLink) for Amazon S3.

C.

Create a Gateway VPC Endpoint for Amazon DynamoDB.

D.

Deploy a NAT Gateway in a public subnet.

E.

Configure an AWS VPN connection to the AWS public zone.

F.

Use AWS Transit Gateway to route traffic to the public internet.

How to approach this question

Identify the two AWS services that support Gateway VPC Endpoints (S3 and DynamoDB).

Full Answer

Amazon S3 and Amazon DynamoDB are the only two services that support Gateway VPC Endpoints. These endpoints are added to the VPC route table, provide secure private access without internet, and are completely free.

Common mistakes

Choosing NAT Gateway, which provides internet access and costs money.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

75 questions · hints · full answers · grading

More questions from this exam