AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

An operations team runs an Auto Scaling group of Linux EC2 instances in two private subnets (one in each Availability Zone) of a VPC. The instances must occasionally download patches from public YUM repositories and read data from an S3 bucket. Each subnet currently uses its own NAT gateway, and the hourly NAT gateway charges are higher than all data-processing fees combined. The team must lower network costs while ensuring that outbound connectivity continues if either Availability Zone becomes unavailable. Which solution meets these requirements while following AWS best practices?

  • Remove the NAT gateways and create an interface VPC endpoint for AWS Systems Manager; configure Patch Manager to download updates through the endpoint.

  • Attach an egress-only internet gateway to the VPC and add a default route from each private subnet to the gateway.

  • Create a gateway VPC endpoint for Amazon S3 and replace each NAT gateway with a small NAT instance in the corresponding Availability Zone. Disable source/destination checks on the instances and update the private route tables to use the new NAT instances.

  • Replace both NAT gateways with a single NAT gateway in one Availability Zone and point the default route of both private subnets to that gateway.

AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot