AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryEasy

A developer has deployed a new application on EC2 instances within a private subnet. The application needs to securely access Amazon S3 and Amazon DynamoDB without traversing the public internet. Which AWS networking component should the SysOps administrator configure to meet this requirement?

  1. AInternet Gateway
  2. BNAT Gateway
  3. CAWS Direct Connect
  4. DVPC Endpoint
Show answer & explanation

Correct answer: D. VPC Endpoint

VPC Endpoints allow you to privately connect your VPC to supported AWS services and VPC endpoint services powered by PrivateLink without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection. Specifically, Gateway Endpoints for S3 and Interface Endpoints for DynamoDB enable secure access from private subnets.

Why the other options are wrong

  • A. Internet Gateway provides internet access; it does not provide private access to AWS services.
  • B. NAT Gateway allows private instances to access the internet but does so via the public internet, which violates the 'without traversing the public internet' requirement.
  • C. Direct Connect connects an on-premises data center to AWS; it's not for connecting instances within a VPC to AWS services privately without the internet.

AWS VPC Endpoints

A feature that enables you to privately connect your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink.

  • Traffic stays within the Amazon network.
  • Eliminates need for Internet Gateway or NAT Gateway for service access.
  • Two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints (for S3, DynamoDB).

Memory trick: VPC Endpoint is your private tunnel to AWS services.

More Networking and Content Delivery questions