AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An Ops team created an interface VPC endpoint for AWS Secrets Manager. Afterward, EC2 instances in private subnets time-out when retrieving secrets. Flow logs show TCP 443 traffic to 52.94.x.x being dropped because the subnets have no NAT or internet gateway. DNS on the instances still resolves secretsmanager.us-east-1.amazonaws.com to public IPs. Which change restores access without sending traffic to the internet?
Create a public Route 53 hosted zone for secretsmanager..amazonaws.com and associate it with the VPC.
Enable Private DNS for the Secrets Manager interface VPC endpoint so that the VPC resolver returns the endpoint's private IP addresses.
Add an outbound rule to the instance security group that allows HTTPS traffic to the VPC endpoint security group.
Update the subnet route table to direct 0.0.0.0/0 traffic to a NAT gateway in a public subnet.
Enabling the Private DNS feature on the interface VPC endpoint makes Route 53 Resolver map the standard regional Secrets Manager hostname to the endpoint's private IP addresses. The HTTPS requests are then delivered directly to the endpoint inside the VPC, so no internet gateway or NAT is required. Changing security-group rules would not alter DNS resolution. Adding a NAT gateway or internet gateway would route the traffic over the public internet, violating the requirement. Creating a public hosted zone does not influence the VPC's internal DNS resolver.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an interface VPC endpoint in AWS?
Open an interactive chat with Bash
What does enabling Private DNS for an endpoint do?
Open an interactive chat with Bash
Why doesn't adding a security group rule or NAT gateway solve the issue?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Networking and Content Delivery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .