Courseiva
Network ImplementationeasyMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company has a VPC with public and private subnets in two Availability Zones. The company hosts a web application on EC2 instances in the private subnets. The application needs to access an S3 bucket. What is the MOST cost-effective and secure way to provide this access?

⚠ Common exam trap

Many candidates confuse VPC Gateway Endpoints with Interface Endpoints or assume a NAT Gateway is required for private subnet internet access, overlooking that S3 can be accessed privately and cost-effectively via a Gateway Endpoint without any NAT or internet gateway.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a VPC Gateway Endpoint for S3 and attach it to the private subnet route tables.

A VPC Gateway Endpoint for S3 provides private, secure connectivity to S3 without traversing the public internet, and it incurs no hourly or data processing charges, making it the most cost-effective and secure choice. Traffic stays within the AWS network, and the endpoint is attached to the private subnet route tables, allowing EC2 instances in those subnets to access S3 directly without needing a NAT Gateway or public IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy a NAT Gateway in each public subnet and route traffic from private subnets through it.

    Why it's wrong here

    Incurs hourly and data processing charges.

  • Use AWS Transit Gateway to route traffic to S3 via a centralized VPN.

    Why it's wrong here

    Over-engineered and costly for a single VPC.

  • Attach an Internet Gateway to the VPC and assign public IPs to the EC2 instances.

    Why it's wrong here

    Exposes instances to the internet, less secure.

  • Create a VPC Gateway Endpoint for S3 and attach it to the private subnet route tables.

    Why this is correct

    Cost-effective and secure; no data transfer costs.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.