AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An application runs in three isolated (private, no internet) subnets of a VPC. The instances reach Amazon S3 through a NAT gateway in a public subnet, generating high data-processing charges. You must ensure the instances continue to reach S3 but no longer traverse the NAT gateway, without exposing them to the internet. Which change to the route tables meets these requirements?

  • Add a route with the S3 prefix list destination that targets a newly created S3 gateway endpoint in the route table associated with the isolated subnets.

  • Replace the NAT gateway with an egress-only internet gateway and add a ::/0 IPv6 default route in the existing route tables.

  • Associate the isolated subnets with the public route table that already has a 0.0.0.0/0 route to the internet gateway.

  • Create an interface VPC endpoint for Amazon S3 and update the instances hosts files to resolve the endpoint's DNS name.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot