Courseiva
Network DesignmediumMultiple SelectObjective-mapped

ANS-C01 Network Design Practice Question

A company has a VPC with public and private subnets. The private subnets must access an S3 bucket without traversing the internet. Which TWO methods can achieve this? (Choose TWO.)

⚠ Common exam trap

Candidates often confuse gateway endpoints with interface endpoints (PrivateLink) or assume that a NAT gateway provides private connectivity, when in fact both gateway endpoints and PrivateLink can achieve private S3 access, but only gateway endpoints are free and do not require an ENI in the subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a VPC gateway endpoint for S3 and associate it with the private subnet route tables.

A VPC gateway endpoint for S3 uses AWS's internal network to route traffic to S3 without traversing the internet. This endpoint is a horizontally scaled, redundant, and highly available gateway that is added to the route table of the private subnets, enabling direct, private connectivity to S3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attach an internet gateway to the VPC and route traffic through it.

    Why it's wrong here

    Traffic exits to the internet.

  • Create a VPC gateway endpoint for S3 and associate it with the private subnet route tables.

    Why this is correct

    Gateway endpoint provides private access to S3.

  • Set up a VPN connection to the on-premises network and access S3 from there.

    Why it's wrong here

    Does not keep traffic within AWS.

  • Use AWS PrivateLink to create a VPC endpoint for the S3 bucket.

    Why this is correct

    PrivateLink allows private connectivity.

  • Place a NAT gateway in the public subnet and route traffic through it.

    Why it's wrong here

    Traffic goes through the internet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,621 original ANS-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on ANS-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company has a VPC with a public subnet and a private subnet. The private subnet needs to access an S3 bucket for backups. Which TWO actions are required to provide private connectivity to S3 without using a NAT Gateway?

hard
  • A.Create a NAT Gateway in the public subnet.
  • B.Create a VPC Gateway Endpoint for S3.
  • C.Add a route for the S3 prefix list in the private subnet route table pointing to the gateway endpoint.
  • D.Create a VPC Interface Endpoint for S3.
  • E.Create a VPC Peering connection to an S3 VPC.

Why B: A VPC Gateway Endpoint provides private connectivity to S3 without traversing the internet or requiring a NAT Gateway. It uses AWS’s internal network to route traffic from the private subnet to S3, ensuring data never leaves the AWS backbone. This is the most cost-effective and secure method for private S3 access within a VPC.

Variation 2. A company has a VPC with a public subnet and a private subnet. The private subnet instances need to access an S3 bucket. Which configuration provides the most secure and efficient access without traversing the internet?

easy
  • A.Establish a VPN connection to on-premises and route to S3 from there.
  • B.Use a NAT Gateway in the public subnet to route traffic to S3.
  • C.Create a VPC Gateway Endpoint for Amazon S3 and associate it with the private subnet route table.
  • D.Configure a proxy server in the public subnet.

Why C: A VPC Gateway Endpoint for Amazon S3 allows instances in a private subnet to access S3 directly over the AWS network without traversing the internet, using a route table entry that targets the endpoint's prefix list. This provides the most secure and efficient access by keeping traffic within the AWS backbone, avoiding NAT Gateway costs and internet exposure.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.