AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignHard

An infrastructure team is deploying a new application that will use a private subnet for its backend services and requires secure access to Amazon S3 and DynamoDB without traversing the public internet. The application must also fetch container images from Amazon ECR. All traffic must remain within the AWS network. Which networking components are required to meet these connectivity requirements?

  1. AInternet Gateway, NAT Gateway, and S3 VPC Endpoint (Gateway Type).
  2. BNAT Gateway, S3 VPC Endpoint (Interface Type), DynamoDB VPC Endpoint (Interface Type), and ECR VPC Endpoint (Interface Type).
  3. CInternet Gateway, S3 VPC Endpoint (Gateway Type), and DynamoDB VPC Endpoint (Gateway Type).
  4. DS3 VPC Endpoint (Gateway Type), DynamoDB VPC Endpoint (Interface Type), and ECR VPC Endpoint (Interface Type).
Show answer & explanation

Correct answer: D. S3 VPC Endpoint (Gateway Type), DynamoDB VPC Endpoint (Interface Type), and ECR VPC Endpoint (Interface Type).

S3 uses a Gateway VPC Endpoint, which is a route table entry and doesn't require ENIs. DynamoDB and ECR require Interface VPC Endpoints, which create ENIs in your subnets. These endpoints ensure private and secure access to the services without using a NAT Gateway or Internet Gateway, keeping all traffic within the AWS network.

Why the other options are wrong

  • A. Internet Gateway exposes the private subnet to the public internet, violating the security requirement. S3 endpoint is correct, but NAT Gateway is not needed for private access if Interface Endpoints are used.
  • B. NAT Gateway is not needed for private access to AWS services using VPC endpoints. S3 uses a Gateway endpoint, not an Interface endpoint.
  • C. Internet Gateway violates the security requirement. DynamoDB uses an Interface endpoint, not a Gateway endpoint.

Private Subnet with VPC Endpoints

Enables private connectivity from a VPC to supported AWS services without requiring an Internet Gateway, NAT device, VPN connection, or AWS Direct Connect.

  • Gateway Endpoints for S3 and DynamoDB (legacy support).
  • Interface Endpoints for most other AWS services (uses PrivateLink).
  • Keeps traffic within the Amazon network, enhancing security.

Memory trick: Endpoints are your private doors to AWS services, without needing the public street.

More Network Design questions