AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A company is designing a new multi-tier application in AWS. The application will have a web tier, an application tier, and a database tier. The web tier instances need to be publicly accessible, while the application and database tiers must remain private. All tiers require access to common AWS services like S3 and DynamoDB without traversing the public internet. The VPC CIDR block is 10.0.0.0/16. What is the most efficient way to ensure private access to S3 and DynamoDB for the private subnets?

  1. ACreate a Transit Gateway and route S3 and DynamoDB traffic through it to dedicated endpoints.
  2. BDeploy VPC Gateway Endpoints for S3 and DynamoDB in the VPC.
  3. CConfigure a NAT Gateway in each private subnet and route traffic for S3 and DynamoDB through it.
  4. DEstablish a Direct Connect connection and route S3 and DynamoDB traffic over it.
Show answer & explanation

Correct answer: B. Deploy VPC Gateway Endpoints for S3 and DynamoDB in the VPC.

VPC Gateway Endpoints allow instances in a VPC to privately connect to supported AWS services like S3 and DynamoDB without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect. This keeps the traffic within the Amazon network, improving security and reducing data transfer costs.

Why the other options are wrong

  • A. Transit Gateway is primarily for inter-VPC or hybrid cloud connectivity, not direct private access to AWS services within a single VPC.
  • C. NAT Gateway is for outbound internet access, not private access to AWS services like S3/DynamoDB, and would incur unnecessary costs.
  • D. Direct Connect is for connecting on-premises networks to AWS, not for private access to AWS services from within a VPC.

VPC Gateway Endpoint

A gateway that you can create in your VPC to enable private connection between your VPC and supported AWS services.

  • Provides private connectivity to S3 and DynamoDB.
  • Traffic stays within the Amazon network.
  • Does not require an Internet Gateway or NAT device.

Memory trick: Endpoints are the 'private doors' to AWS services.

More Network Implementation questions