AWS Certified Solutions Architect Professional SAP-C02 Practice Question

An e-commerce company runs its order-processing microservice on Amazon ECS tasks that use AWS Fargate. The tasks are deployed in private subnets of a VPC that has no internet gateway or NAT gateway. The application must (1) publish custom events to Amazon EventBridge and (2) read and write order metadata in an Amazon DynamoDB table. All traffic to AWS services must stay on the AWS network, and the architecture team wants to minimize any additional data-processing charges for DynamoDB access while keeping operational overhead low. Which network design should a solutions architect implement to meet these requirements?

  • Provision a NAT gateway in a public subnet and point the private subnets' default route to the NAT gateway so the tasks can reach EventBridge and DynamoDB over the internet.

  • Peer the production VPC with a separate VPC that has internet connectivity, and route traffic through the peering connection to access EventBridge and DynamoDB.

  • Create interface VPC endpoints for both EventBridge and DynamoDB in the VPC, and attach restrictive endpoint policies.

  • Create a gateway VPC endpoint for DynamoDB and an interface VPC endpoint for EventBridge in the VPC. Update the route tables and security groups so that the ECS tasks use these endpoints.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot