SAP-C02 Design for New Solutions Practice Question
A company is building a microservices architecture on Amazon ECS. Services need to communicate with each other and with external SaaS applications. The architect must ensure that service discovery is dynamic and that traffic to external services is routed through a single egress point for security and monitoring. Which combination of services should the architect use?
⚠ Common exam trap
Many exam-takers confuse the roles of an Internet Gateway (which allows direct bidirectional internet access) with a NAT gateway (which provides controlled outbound-only egress), and assuming Route 53 can handle dynamic service discovery when it lacks the necessary registration and health-check integration for ephemeral containers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Cloud Map for service discovery and a NAT gateway for egress
AWS Cloud Map is the correct choice for dynamic service discovery in Amazon ECS because it allows services to register themselves with a logical service name and be discovered via DNS or API calls, which is ideal for microservices that scale and change frequently. A NAT gateway provides a single, controlled egress point for outbound traffic to external SaaS applications, enabling centralized security monitoring and consistent IP address management, unlike an Internet Gateway which would expose instances directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Cloud Map for service discovery and a NAT gateway for egress
Why this is correct
AWS Cloud Map registers ECS tasks and resolves them dynamically as they scale, removing hard-coded endpoints, while a NAT gateway gives all tasks a single managed egress IP for external SaaS traffic, satisfying both the dynamic discovery and centralised egress monitoring constraints.
- ✗
Amazon Route 53 for service discovery and an Application Load Balancer for egress
Why it's wrong here
An Application Load Balancer distributes inbound traffic to targets; it cannot perform source NAT for outbound SaaS connections, so no single egress point exists. It is tempting because ALBs front internal services well, which is right when load-balancing inbound requests rather than routing egress.
- ✗
AWS Cloud Map for service discovery and an Internet Gateway for egress
Why it's wrong here
An Internet Gateway gives each subnet a direct route to the internet, so traffic does not funnel through one monitored egress point. It is tempting because it enables outbound connectivity cheaply, which is correct when per-instance public egress is acceptable and no central inspection is required.
- ✗
Amazon Route 53 for service discovery and VPC endpoints for egress
Why it's wrong here
VPC endpoints only reach AWS services, so external SaaS traffic cannot traverse them; a NAT gateway provides the single monitored egress point. Endpoints are tempting because they privately connect to AWS services without internet exposure, which is correct when only internal AWS APIs are consumed.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.