AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A company runs web servers in private subnets across two Availability Zones in a single VPC. Each subnet has a NAT gateway in the same Availability Zone. The instances download hundreds of terabytes of data every month from Amazon S3 within the same AWS Region, and the NAT gateway data-processing charges dominate the network bill. The company wants to minimize ongoing network costs without sacrificing high availability or throughput. Which action will achieve this goal at the lowest cost?
Replace both NAT gateways with burstable t3.micro NAT instances configured in an Auto Scaling group.
Create a VPC gateway endpoint for Amazon S3 in the VPC and update each private subnet's route table to direct S3 traffic to the endpoint.
Provision an AWS Direct Connect public virtual interface to the Region and route S3 traffic over the connection.
Delete one NAT gateway and configure the remaining NAT gateway to serve both subnets, accepting cross-AZ traffic.
A VPC gateway endpoint lets resources in private subnets communicate with Amazon S3 without traversing a NAT device or an internet gateway. Gateway endpoints are implemented redundantly within every Availability Zone and have no hourly or per-GB data-processing fees; you pay only standard S3 request and storage-class data-transfer rates. Updating the route tables to use the endpoint removes all NAT data-processing costs. Deleting one NAT gateway would introduce cross-AZ data-transfer charges for the other Availability Zone, which often exceeds the hourly cost of keeping two NAT gateways. NAT instances still incur EC2 charges and retain inter-AZ data-transfer costs. A Direct Connect public virtual interface requires a dedicated port and does not eliminate regional VPC-to-S3 charges. Therefore, creating the S3 gateway endpoint is the most cost-effective solution.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a VPC gateway endpoint?
Open an interactive chat with Bash
How do you update a private subnet's route table to use a gateway endpoint?
Open an interactive chat with Bash
Why does eliminating NAT gateways reduce data-processing costs?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .