Courseiva
Network ImplementationmediumMultiple ChoiceObjective-mapped

ANS-C01 Network Implementation Practice Question

A company has a VPC with public and private subnets. They have a web server in the public subnet that needs to make API calls to Amazon S3. The web server has a public IP. What is the MOST secure way to allow the web server to access S3 without traversing the internet?

⚠ Common exam trap

Many exam-takers confuse Gateway VPC Endpoints with Interface VPC Endpoints, assuming an interface is needed for all services, but S3 and DynamoDB exclusively use Gateway Endpoints for private connectivity without internet traversal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a Gateway VPC Endpoint for S3 and add a route in the public subnet's route table to S3 via the endpoint

A Gateway VPC Endpoint for S3 allows resources within a VPC to access S3 over the AWS private network without traversing the internet. By adding a route in the public subnet's route table pointing to the endpoint, the web server can reach S3 privately, even though it has a public IP. This is the most secure option because traffic stays within the AWS backbone and does not require an internet gateway, NAT, or proxy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a Gateway VPC Endpoint for S3 and add a route in the public subnet's route table to S3 via the endpoint

    Why this is correct

    Correct; Gateway Endpoint provides private access to S3 without internet.

  • Place a forward proxy server in the public subnet and configure the web server to use it for S3

    Why it's wrong here

    Incorrect; this adds complexity and does not guarantee private access.

  • Create an Interface VPC Endpoint for S3 in the public subnet

    Why it's wrong here

    Incorrect; Interface Endpoint is an option but not the most cost-effective; also it can be used but the question asks for most secure way.

  • Set up a NAT Gateway in the same subnet and route S3 traffic through it

    Why it's wrong here

    Incorrect; NAT Gateway still uses the internet to reach S3.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.