A company accesses a SaaS application hosted behind an NLB via AWS PrivateLink (interface endpoint) from its VPC. After adding a new Availability Zone and new subnets, the engineer cannot create an interface VPC endpoint in the new AZ. What is the likely cause?
Choose an answer
Tap an option to check your answer.
Correct answer: The SaaS provider does not offer the solution in the new Availability Zone and has not configured cross-zone load balancing for the NLB..
Why this is the answer
Interface VPC endpoints (PrivateLink) require the service provider to make their service available in the Availability Zones where the endpoint is created. If the SaaS provider has not extended their service (and underlying NLB configuration) to the new Availability Zone, you won't be able to create an endpoint there. Cross-zone load balancing on the NLB is also crucial; without it, traffic might not be routed correctly if the service isn't explicitly available in that AZ. The CIDR block conflict is unlikely to prevent endpoint creation, though it could cause routing issues later. DNS attributes are VPC-wide, not subnet-specific, and are usually enabled by default for new VPCs. An internet gateway route is irrelevant for PrivateLink, as traffic stays within the AWS network.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed