AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
Your company runs an Amazon EKS cluster in private subnets with no outbound internet access. You need to forward Prometheus metrics from the cluster to an existing Amazon Managed Service for Prometheus (AMP) workspace in the same AWS account and Region. Traffic must stay within the VPC and the solution should impose minimal operational overhead. Which approach meets these requirements?
Deploy a NAT gateway in the private subnet so Prometheus can reach the public AMP endpoint over the internet.
Create interface VPC endpoints for com.amazonaws..aps-workspaces (and optionally com.amazonaws..aps), enable private DNS, and update the Prometheus remote_write URL to use the workspace endpoint.
Enable VPC Flow Logs and configure the CloudWatch agent to forward the metrics to the AMP workspace.
Push metrics to Amazon CloudWatch and configure a CloudWatch metric stream to forward them to the AMP workspace.
Amazon Managed Service for Prometheus supports AWS PrivateLink. Creating interface VPC endpoints for the APS dataplane (com.amazonaws..aps-workspaces) and, optionally, the APS control plane (com.amazonaws..aps) exposes private DNS names that Prometheus can use in its remote_write URL. All traffic is routed through the interface endpoints rather than an internet gateway or NAT device, so it never leaves the AWS network and requires no additional infrastructure.
Using a NAT gateway sends traffic to the public AMP endpoint and incurs additional cost. VPC Flow Logs and the CloudWatch agent cannot forward Prometheus metrics directly to AMP, and CloudWatch metric streams do not transport Prometheus data. Therefore, the PrivateLink VPC endpoint solution is the only one that satisfies the requirements.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS PrivateLink?
Open an interactive chat with Bash
What is an Interface VPC Endpoint?
Open an interactive chat with Bash
What is Prometheus remote_write URL, and how does it work?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Monitoring, Logging, Analysis, Remediation, and Performance Optimization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .