AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationEasy
A data analytics company needs to process large datasets stored in Amazon S3 from EC2 instances in a private subnet. To ensure data privacy and reduce data transfer costs, all S3 traffic must remain within the AWS network and not traverse the public internet. Which type of VPC Endpoint should be configured?
- AInterface Endpoint
- BClient VPN Endpoint
- CGateway Load Balancer Endpoint
- DGateway Endpoint
Show answer & explanationAnswer & explanation
Correct answer: D. Gateway Endpoint
A Gateway Endpoint is specifically designed for Amazon S3 and DynamoDB, allowing private access to these services from within a VPC without traversing the public internet. It's configured as a route table entry.
Why the other options are wrong
- A. Interface Endpoints are powered by AWS PrivateLink and are used for a wide range of AWS services and custom services, but Gateway Endpoints are specifically for S3 and DynamoDB at lower cost.
- B. Client VPN Endpoints are for remote user access, not for VPC instances accessing S3 privately.
- C. Gateway Load Balancer Endpoints are used with Gateway Load Balancers for inserting network appliances, not for direct private access to S3.
VPC Gateway Endpoint
A VPC Gateway Endpoint allows private connectivity from your VPC to Amazon S3 and DynamoDB without requiring an Internet Gateway, NAT device, or VPN connection.
- Supports Amazon S3 and DynamoDB only
- Configured as a route table entry
- Does not use Elastic Network Interfaces (ENIs)
- Free to use, only pay for S3/DynamoDB service usage
Memory trick: Gateway Endpoints are the private S3/DynamoDB shortcut.