ANS-C01 exam dumps

ANS-C01 practice question 357 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 357

Select 2

Your organization has deployed a custom web service in a private subnet of a VPC. The service needs to be accessed privately by applications running in other VPCs within the same AWS Region and by on-premises applications over an AWS Direct Connect connection. Which of the following approaches will allow secure and private access to the service?

  1. A

    Use AWS PrivateLink to create an interface endpoint for the service and share it with the required VPCs and on-premises networks.

  2. B

    Establish VPC peering connections between the VPC hosting the service and each of the other VPCs, then configure a VPN connection for on-premises access.

  3. C

    Create a public-facing Application Load Balancer (ALB) in front of the service and restrict access using security groups.

  4. D

    Use an AWS Transit Gateway to route traffic between the VPCs and connect the Direct Connect gateway for on-premises access.

  5. E

    Expose the service using an Elastic IP and route traffic through a Network Load Balancer (NLB) for private access.

Show answer and explanation

Correct answers: A, D

Explanation

To enable private and secure access to a custom service deployed in a VPC from other VPCs and on-premises environments, AWS PrivateLink and AWS Transit Gateway are the most effective solutions. AWS PrivateLink provides private connectivity via interface endpoints, and AWS Transit Gateway simplifies routing at scale while maintaining privacy. VPC peering lacks scalability, and public-facing configurations like Elastic IPs or ALBs do not meet the private access requirement.

  • A. Correct.

    Correct: AWS PrivateLink allows you to create an interface endpoint for your service, enabling private access from other VPCs and on-premises environments via Direct Connect. It is a scalable and secure option for private connectivity.

  • B. Incorrect.

    Partially correct but not optimal: While VPC peering can enable private access between VPCs, it requires individual peering connections for each VPC, which does not scale well. Additionally, it does not natively support on-premises access without complex configurations like VPN.

  • C. Incorrect.

    Incorrect: A public-facing ALB does not provide private access. Even with security groups, the service would be exposed to the public internet, which does not meet the requirement for private access.

  • D. Correct.

    Correct: AWS Transit Gateway can simplify network routing between multiple VPCs and on-premises environments using Direct Connect. It provides a scalable and private way to access the service.

  • E. Incorrect.

    Incorrect: Elastic IPs and NLBs are public-facing by default when used in this manner. This approach would not provide private access to the service.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam