For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 5Question 15
    Medium1 markMultiple Choice
    Domain 1.1: Network ConnectivityNetworkingPrivateLinkSecurity

    AWS SAP-C02 · Question 15 · Domain 1.1: Network Connectivity

    A security architect is reviewing an AWS environment. Applications in VPC A need to access a third-party SaaS service hosted in VPC B (owned by a different AWS account). The SaaS provider requires that traffic must not traverse the public internet. The SaaS service must be highly available, and the consumer (VPC A) must not have access to any other resources in VPC B. Which solution is the MOST secure and scalable?

    Answer options:

    A.

    The SaaS provider creates an AWS PrivateLink endpoint service backed by a Network Load Balancer in VPC B. The consumer creates an interface VPC endpoint in VPC A.

    B.

    Set up VPC peering between VPC A and VPC B. Update route tables to direct traffic to the SaaS application instances.

    C.

    Deploy an AWS Transit Gateway and attach both VPCs. Use Transit Gateway route tables to restrict access to the specific SaaS application subnets.

    D.

    Create a Site-to-Site VPN connection between Virtual Private Gateways attached to VPC A and VPC B.

    How to approach this question

    Identify the AWS service designed specifically for secure, unidirectional SaaS service consumption across accounts.

    Full Answer

    A.The SaaS provider creates an AWS PrivateLink endpoint service backed by a Network Load Balancer in VPC B. The consumer creates an interface VPC endpoint in VPC A.✓ Correct
    The SaaS provider creates an AWS PrivateLink endpoint service backed by a Network Load Balancer in VPC B. The consumer creates an interface VPC endpoint in VPC A.
    AWS PrivateLink allows you to privately access services hosted on AWS in a highly available and scalable manner, without using public IPs and without requiring the traffic to traverse the internet. It provides unidirectional access, meaning the consumer can access the service, but the provider cannot initiate connections to the consumer.

    Common mistakes

    Choosing VPC Peering, which provides bidirectional access to the entire VPC.
    Question 14All questionsQuestion 16

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 5

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is redesigning its AWS network architecture across 50 AWS accounts and 3 AWS ...HardQ02A company uses AWS Organizations to manage multiple accounts. The security team mandates that no ...MediumQ03A financial institution requires a disaster recovery strategy for its critical trading applicatio...HardQ04An enterprise is setting up a new multi-account AWS environment using AWS Control Tower. They nee...MediumQ05A company has a complex AWS environment with hundreds of linked accounts under AWS Organizations....Hard
    View all 75 questions →