Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SAP-C02 Exam - Topic 1 Question 65 Discussion

A company hosts a metadata API on Amazon EC2 instances behind an internet-facing Application Load Balancer (ALB). Only internal applications that run on EC2 instances in separate AWS accounts need to access the metadata API. All the internal EC2 instances use NAT gateways. A new policy requires that traffic between internal applications must not travel across the public internet. Which solution will meet this requirement?
D) Create an internal ALB. Register the metadata API's EC2 instances with the internal ALB. Configure an AWS PrivateLink endpoint service for the internal ALB. Grant the internal applications access to the metadata API through the PrivateLink endpoint. Explanation: Creating an internal ALB and configuring it as a PrivateLink endpoint service enables private connectivity between internal applications and the metadata API, ensuring that traffic does not traverse the public internet. Internal ALB: Ensures traffic stays within the AWS network and is not exposed publicly. PrivateLink endpoint service: Provides secure, private access to the ALB from the internal EC2 instances in other AWS accounts. Traffic stays within the AWS global network, leveraging AWS security best practices and meeting the new policy requirements for no public internet exposure. This approach is secure, scalable, and minimizes management complexity compared to API Gateway solutions.
A) Create an HTTP API in Amazon API Gateway. Configure a route for the metadata API. Configure a VPC link to the VPC that hosts the metadata API's EC2 instances. Update the API Gateway resource policy to include the account IDs of the internal applications that access the metadata API.
B) Create a REST API in Amazon API Gateway. Specify the API Gateway endpoint type as private. Associate the REST API with the metadata API's VPC. Create a gateway VPC endpoint for the REST API. Share the endpoint across accounts by using AWS Resource Access Manager (AWS RAM). Configure the internal applications to connect to the gateway VPC endpoint.
C) Create an internal ALB. Register the metadata API's EC2 instances with the internal ALB. Create an internal Network Load Balancer (NLB) that has a target group type of ALB. Register the internal ALB as the target. Configure an AWS PrivateLink endpoint service for the NLB. Grant the internal applications access to the metadata API through the PrivateLink endpoint.

Amazon SAP-C02 Exam - Topic 1 Question 65 Discussion

Actual exam question for Amazon's SAP-C02 exam
Question #: 65
Topic #: 1
[All SAP-C02 Questions]

A company hosts a metadata API on Amazon EC2 instances behind an internet-facing Application Load Balancer (ALB). Only internal applications that run on EC2 instances in separate AWS accounts need to access the metadata API. All the internal EC2 instances use NAT gateways. A new policy requires that traffic between internal applications must not travel across the public internet. Which solution will meet this requirement?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Stacey
24 days ago
Surprised they didn't mention just using a VPC peering connection!
upvoted 0 times
...
Alyssa
29 days ago
I think C is a bit overkill for this scenario.
upvoted 0 times
...
Dalene
1 month ago
Option B looks solid for private access!
upvoted 0 times
...
Francine
1 month ago
I heard API Gateway can add unnecessary complexity, so B might not be ideal.
upvoted 0 times
...
Cristina
1 month ago
Totally agree, D keeps everything internal and secure!
upvoted 0 times
...
Delmy
2 months ago
Wait, can we really trust PrivateLink for all use cases?
upvoted 0 times
...
Claudia
2 months ago
I think D is the best choice for simplicity and security.
upvoted 0 times
...
Deandrea
2 months ago
Option B seems solid with the private endpoint setup.
upvoted 0 times
...
Hubert
2 months ago
I think option A is less likely to be correct since it involves an HTTP API and doesn't mention PrivateLink, which I believe is crucial for this scenario.
upvoted 0 times
...
Elina
2 months ago
I'm a bit confused about the differences between the internal ALB and the NLB in options C and D. I feel like both could work, but I can't recall which one is more efficient.
upvoted 0 times
...
Jennie
3 months ago
I remember practicing a question about using PrivateLink, which seems relevant here. Option D might be the right choice since it directly mentions an internal ALB and PrivateLink.
upvoted 0 times
...
Hollis
3 months ago
I think option B sounds familiar because it mentions a private API Gateway, but I'm not sure if it's the best fit for keeping traffic off the public internet.
upvoted 0 times
...

Save Cancel