ANS-C01 exam dumps

ANS-C01 practice question 356 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 356

Select 2

Your company has deployed a custom API service in a VPC. The service needs to be securely accessed by other VPCs within the same AWS Region, as well as by external clients over the internet. Which combination of solutions would allow both secure private access for VPCs and public access for external clients?

  1. A

    Use an Amazon API Gateway with a VPC Link for private VPC access and configure a public endpoint for external clients.

  2. B

    Establish VPC peering between the VPC hosting the service and all other VPCs, and use an Elastic Load Balancer with a public IP for external clients.

  3. C

    Deploy AWS PrivateLink (VPC endpoint service) for private VPC access and use an Elastic Load Balancer with a public IP for external clients.

  4. D

    Route all traffic (both internal and external) through a NAT Gateway in the VPC where the custom service is deployed.

  5. E

    Use AWS Transit Gateway for internal VPC access and configure a public endpoint with Amazon CloudFront for external clients.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the requirements of secure private access for internal VPCs and public access for external clients, a combination of solutions is needed. Amazon API Gateway with a VPC Link or AWS PrivateLink provides secure private access for internal VPCs, while a public-facing Elastic Load Balancer or API Gateway endpoint meets the need for external access. These approaches are scalable, secure, and aligned with AWS best practices.

  • A. Correct.

    This is correct. Amazon API Gateway with a VPC Link provides a secure method for private VPC access, and configuring a public endpoint allows access for external clients over the internet.

  • B. Incorrect.

    This is not the best solution as VPC peering does not scale well with a large number of VPCs, and it does not inherently handle public access for external clients.

  • C. Correct.

    This is correct. AWS PrivateLink enables secure private access from other VPCs, and an Elastic Load Balancer with a public IP allows internet-facing access for external clients.

  • D. Incorrect.

    This is incorrect. A NAT Gateway is used for outbound traffic from private subnets and is not designed for routing both internal and external access to a service.

  • E. Incorrect.

    This is partially correct but not optimal. AWS Transit Gateway can connect multiple VPCs, but it does not inherently provide public access. Amazon CloudFront provides public access but is not needed when simpler solutions like a public Elastic Load Balancer or API Gateway are available.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam