AWS SAP-C02 · Question 56 · Domain 1.1: Network Connectivity
An architect is designing a secure VPC architecture. The VPC contains private subnets with EC2 instances that need to download software patches from Amazon S3 and access Amazon DynamoDB. The instances must NOT have internet access. Which TWO solutions provide the MOST secure and cost-effective connectivity? (Select TWO)
Answer options:
Create a Gateway VPC Endpoint for Amazon S3.
Create an Interface VPC Endpoint (AWS PrivateLink) for Amazon S3.
Create a Gateway VPC Endpoint for Amazon DynamoDB.
Deploy a NAT Gateway in a public subnet.
Configure an AWS VPN connection to the AWS public zone.
Use AWS Transit Gateway to route traffic to the public internet.
75 questions · hints · full answers · grading