An image-processing service runs in a VPC across two Availability Zones. Each AZ has a public and a private subnet. EC2 instances run in the private subnets and are fronted by an ALB in the public subnets. The service needs internet access and uses two NAT gateways. Images are stored in Amazon S3 and the EC2 instances retrieve approximately 1 ■■ of data from the S3 bucket each day. The company emphasizes a high security posture. The solutions architect must minimize costs without weakening security or increasing operational overhead. Which solution meets the requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an S3 gateway VPC endpoint in the VPC and attach an endpoint policy that allows the required S3 actions on the bucket..
Why this is the answer
Creating an S3 gateway VPC endpoint allows the EC2 instances in private subnets to access S3 directly without traversing NAT gateways or the public internet. This enhances security by keeping traffic within the AWS network, reduces costs by eliminating NAT gateway data processing charges for S3 traffic, and maintains operational overhead. Replacing NAT gateways with NAT instances increases operational overhead and can be less scalable. Moving EC2 instances to public subnets weakens security. Attaching an Amazon EFS file system is not relevant for accessing images stored in S3 and introduces unnecessary complexity and cost.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed