ANS-C01 exam dumps

ANS-C01 practice question 247 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 247

Select 3

You are designing a secure architecture for an internal application hosted in your VPC that needs to communicate with a third-party SaaS provider's service. The SaaS provider has set up an interface VPC endpoint using AWS PrivateLink. Which of the following are required to securely connect your application to the SaaS provider's service over PrivateLink?

  1. A

    Ensure the subnet where the interface VPC endpoint is created has a route to the internet.

  2. B

    Create a security group rule to allow traffic from your application to the interface VPC endpoint.

  3. C

    Ensure DNS resolution is enabled for the interface VPC endpoint in your VPC.

  4. D

    Update the SaaS provider's service to configure a public IP for communication.

  5. E

    Attach an endpoint policy to the interface VPC endpoint to control access.

Show answer and explanation

Correct answers: B, C, E

Explanation

AWS PrivateLink enables private connectivity between your VPC and a SaaS provider's service using interface VPC endpoints. To establish this connection, you must configure security groups to allow traffic, enable DNS resolution for the endpoint, and optionally apply an endpoint policy for fine-grained access control. Internet access and public IPs are not required, as all communication happens over the private network facilitated by AWS PrivateLink.

  • A. Incorrect.

    Incorrect. Interface VPC endpoints do not require internet access to function as they rely on AWS PrivateLink for private communication.

  • B. Correct.

    Correct. You need to configure security group rules to allow traffic from your application to the interface VPC endpoint for proper connectivity.

  • C. Correct.

    Correct. Enabling DNS resolution ensures that the domain name of the SaaS service resolves to the private IP of the interface VPC endpoint.

  • D. Incorrect.

    Incorrect. AWS PrivateLink eliminates the need for public IPs as it facilitates private communication between the VPC and the SaaS provider's service.

  • E. Correct.

    Correct. Attaching an endpoint policy allows you to control which actions and resources are accessible via the interface VPC endpoint.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam