DVA-C02 Development with AWS Services Practice Question
An application running on Amazon EC2 instances in an Auto Scaling group processes messages from an SQS queue. The application runs in a private subnet and needs to send metrics to Amazon CloudWatch. How can the developer ensure the EC2 instances can send metrics without traversing the internet?
⚠ Common exam trap
Candidates often confuse VPC Endpoints with NAT Gateways or Internet Gateways, mistakenly thinking that any outbound traffic to AWS services requires internet access. Additionally, remember that CloudWatch uses an Interface Endpoint (AWS PrivateLink), whereas Gateway Endpoints are only available for Amazon S3 and DynamoDB.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC Endpoint for CloudWatch (com.amazonaws.region.monitoring).
A VPC Endpoint for CloudWatch (com.amazonaws.region.monitoring) allows EC2 instances in a private subnet to send metrics to CloudWatch over the AWS network without traversing the internet. This is achieved by creating an Interface Endpoint (powered by AWS PrivateLink) that provides private connectivity to CloudWatch using private IP addresses from your subnet, avoiding the need for an internet gateway, NAT gateway, or virtual private gateway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach a NAT Gateway to the private subnet and update the route table.
Why it's wrong here
A NAT Gateway allows instances in private subnets to initiate outbound connections to the internet, including public AWS service endpoints. However, the traffic still traverses the public internet to reach CloudWatch, which does not satisfy a requirement for *private* connectivity within the AWS network. This approach introduces an internet egress point, potentially increasing security exposure and data transfer costs.
- ✗
Install the CloudWatch agent on each instance and configure it to use a proxy.
Why it's wrong here
While the CloudWatch agent is necessary to collect metrics and logs, merely configuring it to use a proxy server does not inherently establish private connectivity to CloudWatch. The proxy itself would still require a network path to CloudWatch, either via the public internet or through an existing private connection like a VPC Endpoint or Direct Connect, which this option does not provide. This solution only intermediates traffic, it doesn't create the private network path.
- ✗
Attach an Internet Gateway to the VPC and assign public IPs to instances.
Why it's wrong here
Attaching an Internet Gateway to the VPC and assigning public IP addresses to EC2 instances places them in a public subnet, allowing direct internet access. While this enables communication with CloudWatch's public endpoints, it exposes the instances directly to the public internet, which is generally undesirable for security and compliance reasons, especially when private connectivity is preferred or required. This approach bypasses the need for private subnets entirely, sacrificing isolation.
- ✓
Create a VPC Endpoint for CloudWatch (com.amazonaws.region.monitoring).
Why this is correct
Creating a VPC Endpoint for CloudWatch, specifically an interface endpoint using the `com.amazonaws.region.monitoring` service name, establishes a private connection between your VPC and CloudWatch. This allows EC2 instances in private subnets to send metrics and logs to CloudWatch entirely within the AWS network, bypassing the public internet. This solution significantly enhances security and compliance by keeping all traffic private and eliminating internet egress for this communication.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.