AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A global enterprise is architecting a multi-account AWS environment. A central 'Shared Services' VPC hosts centralized tools. Numerous 'Application' VPCs, each in a separate AWS account, host business applications. The EC2 instances in these Application VPCs require frequent access to Amazon S3 and Amazon DynamoDB. The networking team has raised concerns about IP address exhaustion in the Application VPCs. Security requirements mandate that all traffic to S3 and DynamoDB must remain within the AWS network and be restricted to a specific list of approved resources. Which network design should a solutions architect recommend to meet these requirements in the most scalable and resource-efficient manner?

  • In each Application VPC, create VPC Interface Endpoints for both Amazon S3 and Amazon DynamoDB. Attach an endpoint policy to each endpoint to restrict access to the approved resources.

  • In each Application VPC, create VPC Gateway Endpoints for both Amazon S3 and Amazon DynamoDB. Attach an endpoint policy to each endpoint that explicitly allows access only to the approved S3 buckets and DynamoDB tables.

  • Create VPC Interface Endpoints for S3 and DynamoDB in the central Shared Services VPC. Use AWS Transit Gateway to connect all Application VPCs to the Shared Services VPC and route all AWS service traffic through the centralized endpoints.

  • In each Application VPC, configure a NAT Gateway in a public subnet and update the route tables for the private subnets to direct S3 and DynamoDB traffic through the NAT Gateway.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot