AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A company runs more than 20 microservices on Amazon EKS. Each cluster resides in its own VPC and in a different AWS account. Developers need to invoke other microservices by DNS name, without having to know or manage VPC CIDR blocks. All service-to-service traffic must be encrypted in transit, and network administrators must be able to apply fine-grained IAM authorization so that only approved callers can reach specific microservices. The architecture team also wants to avoid running sidecar proxies or modifying the Amazon VPC CNI plug-in and to minimize the effort required to add new accounts and clusters.

Which solution meets all of these requirements with the LEAST operational overhead?

  • Create an Amazon VPC Lattice service network that is shared with all accounts. Associate each cluster's VPC to the service network and register every microservice as a VPC Lattice service target group.

  • Attach all VPCs to an AWS Transit Gateway, expose each microservice through a Network Load Balancer, and create private Route 53 records that point to the load-balancer DNS names. Control access with security groups.

  • For each microservice, create an interface endpoint service with AWS PrivateLink, share the endpoint with other accounts through AWS Resource Access Manager, and use Route 53 private DNS names for discovery.

  • Deploy the open-source Istio service mesh in every EKS cluster and configure a multi-primary mesh across clusters by using VPC peering for inter-cluster traffic.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot