AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A company operates hundreds of Amazon EC2 instances in private subnets across three production VPCs in the us-east-1 Region. The instances must receive Run Command instructions and software patches by using AWS Systems Manager and must also upload command output logs to an Amazon S3 bucket in the same Region. A new security policy forbids any traffic from these subnets from traversing a NAT gateway, internet gateway, or public IP address. The networking team also wants every AWS SDK call that the instances make to resolve to private IP addresses inside the VPCs and to minimize ongoing data-processing charges.

Which solution meets these requirements while providing the lowest operational cost?

  • Keep the NAT gateways in place but attach an S3 gateway endpoint to each route table. Add an IAM policy to every instance profile that denies access to public IP addresses.

  • In each VPC create gateway VPC endpoints for Amazon S3, AWS Systems Manager, and Amazon EC2. Update the private subnet route tables to point traffic for these services to the gateway endpoints and delete the NAT gateways.

  • In each VPC create interface VPC endpoints for SSM, SSMMessages, and EC2Messages, enable private DNS for the endpoints, and attach an endpoint policy that allows only the required Systems Manager actions. Create a gateway VPC endpoint for Amazon S3 and add it to the route tables used by the private subnets. Remove the NAT gateway routes.

  • Create an endpoint service (AWS PrivateLink) for Systems Manager and S3 in a shared-services VPC, share the service with the other VPCs by using AWS RAM, and create Route 53 private hosted zone records that map the public service domains to the endpoint's private IP addresses. Remove the NAT gateways.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot