Your organization disallows direct internet access from managed notebook instances but still needs to use the managed ML service. How can you enable the managed service without granting internet access to the notebook instances?
Choose an answer
Tap an option to check your answer.
Correct answer: Create VPC interface endpoints for the managed ML service inside the corporate VPC..
Why this is the answer
Creating VPC interface endpoints (powered by AWS PrivateLink) for the managed ML service inside your corporate VPC allows private connectivity between your VPC and the AWS service. This means traffic from your notebook instances to the managed ML service traverses the AWS network privately, without needing an internet gateway or NAT gateway, thus adhering to the no-direct-internet-access policy. A NAT gateway provides outbound internet access, which is precisely what the organization wants to avoid for the notebook instances. Routing traffic through an on-premises network would be complex and inefficient for a cloud-native service. Peering with the provider's VPC is not how AWS services are typically accessed privately; PrivateLink through interface endpoints is the standard and secure method for this use case.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed