AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company hosts an internal REST API on Amazon EC2 instances in a "service VPC" that resides in Account A. Several developer teams in other AWS accounts need to consume this API from private subnets in their own VPCs. Security policy states that traffic must stay on the AWS network, the service VPC must not accept any inbound connections over VPC peering, and each consumer VPC must be able to use its own CIDR range without overlap constraints. Which approach satisfies the requirements with the least operational effort?
Expose the API through an internet-facing Application Load Balancer and require each consumer subnet to use a NAT gateway for outbound calls.
Establish VPC peering connections between the service VPC and every consumer VPC, then update route tables to point traffic to the peering links.
Attach all VPCs to an AWS Transit Gateway and advertise the service VPC subnet routes to the consumer VPCs through Transit Gateway route tables.
Place the API behind a Network Load Balancer, create a VPC endpoint service, and let each consumer VPC connect through an interface VPC endpoint (AWS PrivateLink).
Publishing the API through AWS PrivateLink keeps all traffic on the AWS backbone and removes the need to manage complex routing rules or overlapping CIDRs. The service owner places the API behind a Network Load Balancer and creates a VPC endpoint service. Consumer accounts create interface VPC endpoints in their private subnets; these appear as elastic network interfaces, so no inbound traffic reaches the service VPC directly. VPC peering and Transit Gateway attachments fail the inbound-restriction or CIDR-overlap requirements, and a NAT gateway plus public ALB forces traffic across the public internet and adds needless cost.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS PrivateLink and how does it help in this scenario?
Open an interactive chat with Bash
What are the benefits of using a Network Load Balancer with AWS PrivateLink?
Open an interactive chat with Bash
Why are VPC peering and Transit Gateway not suitable for this use case?
Open an interactive chat with Bash
What is AWS PrivateLink and how does it work?
Open an interactive chat with Bash
Why is a Network Load Balancer required for AWS PrivateLink?
Open an interactive chat with Bash
How does AWS PrivateLink address overlapping CIDR issues and enforce inbound restrictions?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .