SOA-C02 exam dumps

SOA-C02 practice question 232 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 232

Single answer

A company has deployed a web application in a VPC that needs to securely connect to a third-party API over the internet without exposing the application to public access. The application is hosted on private subnets, and the company wants to maintain a high level of security and control over outbound traffic. Which networking configuration should you implement to meet these requirements?

  1. A

    Create a NAT Gateway in a public subnet and configure route tables for the private subnets to route internet-bound traffic through the NAT Gateway.

  2. B

    Attach an Internet Gateway to the VPC and associate it with the private subnets to allow outbound internet traffic.

  3. C

    Deploy an AWS PrivateLink endpoint to connect to the third-party API without requiring internet access.

  4. D

    Configure an Elastic Load Balancer (ELB) in the public subnet and route all outgoing traffic through the ELB.

Show answer and explanation

Correct answer: A

Explanation

To securely connect to a third-party API from private subnets without exposing the application to the internet, the best practice is to use a NAT Gateway. It enables outbound internet traffic from private instances while keeping them secure and unreachable from the internet. Other options either expose the private instances or do not fulfill the requirement for connecting to a third-party API.

  • A. Correct.

    This is the correct solution. A NAT Gateway allows instances in private subnets to access the internet for outbound traffic while keeping them private and not directly exposed to the internet.

  • B. Incorrect.

    Incorrect. An Internet Gateway enables direct public internet access, which would expose the private subnets and compromise security requirements.

  • C. Incorrect.

    Incorrect. AWS PrivateLink is used to securely connect to specific AWS services or private endpoints, but it cannot be used to connect to a third-party API hosted on the internet.

  • D. Incorrect.

    Incorrect. An Elastic Load Balancer is designed to distribute incoming traffic to targets but is not used for routing outbound internet traffic from private subnets.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam