ANS-C01 exam dumps

ANS-C01 practice question 249 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 249

Single answer

A company has deployed a private web application in an Amazon VPC. The application needs to be accessed securely by multiple external customers without exposing it to the public internet. The company wants to ensure that each customer has isolated network access to the application. Which solution should you implement to meet these requirements?

  1. A

    Use an Application Load Balancer (ALB) with security groups to restrict access from specific customer IP ranges.

  2. B

    Deploy an AWS PrivateLink endpoint service in your VPC and provide each customer with an endpoint in their respective VPCs.

  3. C

    Set up an AWS Direct Connect connection for each customer and route traffic to the application through a private VPC peering connection.

  4. D

    Expose the application publicly through an API Gateway and use resource policies to restrict access to customer IP ranges.

Show answer and explanation

Correct answer: B

Explanation

AWS PrivateLink is the best solution for securely sharing a private application with multiple customers while maintaining network isolation. By creating an endpoint service in the application VPC, the company can allow customers to connect to the service using interface endpoints in their own VPCs. This approach ensures that the application is not exposed to the public internet and that each customer's traffic is isolated.

  • A. Incorrect.

    This option does not provide the required isolated network connectivity for each customer. Security groups can restrict access, but this does not fulfill the requirement for private, isolated network access.

  • B. Correct.

    AWS PrivateLink allows you to securely expose your application as an endpoint service in your VPC. Customers can connect through their own VPCs using interface endpoints, ensuring network isolation and secure private connectivity.

  • C. Incorrect.

    While AWS Direct Connect can provide private connectivity, it is not scalable or cost-efficient for multiple customers. Additionally, private VPC peering does not allow for one-to-many relationships, which makes it unsuitable for this use case.

  • D. Incorrect.

    Exposing the application publicly through an API Gateway does not meet the requirement for private connectivity. Even with resource policies, this would expose the application to the public internet, which violates the company's requirements.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam