DVA-C02 Development with AWS Services Practice Question
A developer is using Amazon API Gateway to expose a Lambda function as a REST API. The API should only be accessible from a specific VPC. Which TWO steps are required to achieve this? (Choose TWO.)
⚠ Common exam trap
Watch out — candidates often think enabling the Lambda function to be VPC-enabled (Option D) is sufficient to restrict API access, but this only affects the Lambda's outbound connectivity, not the inbound API Gateway endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC endpoint for API Gateway.
Creating a VPC endpoint for API Gateway (of type `execute-api`) allows API Gateway to be accessed privately from within a specific VPC without traversing the public internet. This endpoint uses AWS PrivateLink to provide a private IP address within the VPC, ensuring traffic stays within the AWS network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VPC endpoint for API Gateway.
Why this is correct
Creating an interface VPC endpoint for API Gateway establishes a private connection from your VPC to the API Gateway service using AWS PrivateLink. This allows clients within your VPC to access the API Gateway endpoint without traversing the public internet, ensuring that all traffic remains within the AWS network and is restricted to the specified VPC.
- ✓
Attach a resource policy to the API Gateway API that denies access unless the request originates from the VPC.
Why this is correct
Attaching a resource policy to the API Gateway API allows you to define explicit access rules based on the source of the request. By specifying conditions such as "aws:SourceVpc" or "aws:SourceIp" within the policy, you can deny all requests unless they originate from the designated VPC, effectively restricting access to private network origins.
- ✗
Use an API key that is only known within the VPC.
Why it's wrong here
API keys are primarily used for client authentication, usage plan enforcement, and throttling, not for network-level access control. While an API key can be kept secret within a VPC, it does not inherently restrict access to the API Gateway based on the request's network origin; if the key is compromised, it can be used from any location.
- ✗
Configure the Lambda function to be VPC-enabled.
Why it's wrong here
Configuring a Lambda function to be VPC-enabled allows the function to access resources within a specified VPC, such as databases or private services, by placing its network interfaces inside the VPC. However, this configuration only governs the Lambda function's *outbound* network access and does not impose any restrictions on *inbound* access to the API Gateway endpoint that invokes the Lambda function.
- ✗
Create a VPC endpoint for Lambda.
Why it's wrong here
AWS Lambda functions are serverless compute services that do not expose a direct network endpoint for private access via a VPC endpoint. While Lambda functions can be configured to operate *within* a VPC to access private resources, there is no concept of creating a VPC endpoint *for* Lambda itself to restrict access to the function's invocation endpoint.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.