Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

A company is designing a new application that will process sensitive financial transactions. The application must be deployed in a VPC with no public internet access. The application needs to send logs to Amazon CloudWatch Logs and store files in Amazon S3. Which set of actions should be taken to meet these requirements without allowing internet access?

⚠ Common exam trap

Test-takers frequently assume AWS PrivateLink can be used for both S3 and CloudWatch Logs uniformly, but S3 primarily uses Gateway VPC endpoints (not Interface endpoints) for private access, and PrivateLink is the mechanism for Interface endpoints only.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Gateway VPC endpoint for S3 and an Interface VPC endpoint for CloudWatch Logs

A Gateway VPC endpoint for S3 allows private connectivity to S3 without traversing the internet, using route table entries. An Interface VPC endpoint for CloudWatch Logs, powered by AWS PrivateLink, enables private HTTPS connections to the CloudWatch Logs API without requiring a NAT gateway or internet gateway. Together, these endpoints satisfy the requirement for a VPC with no public internet access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Gateway VPC endpoint for S3 and an Interface VPC endpoint for CloudWatch Logs

    Why this is correct

    Gateway VPC endpoints route S3 traffic privately over the AWS network, while Interface VPC endpoints (powered by AWS PrivateLink) provide private connectivity to CloudWatch Logs. Together they satisfy the no-public-internet constraint for both logging and object storage.

  • ✗

    Place the application behind a public Application Load Balancer

    Why it's wrong here

    A public Application Load Balancer requires internet-facing subnets and an internet gateway, which directly violates the no-public-internet-access requirement. Sending logs to CloudWatch Logs and storing objects in S3 from an isolated VPC is achieved with VPC endpoints (interface endpoints for CloudWatch Logs and a gateway endpoint for S3), keeping traffic on the AWS network.

  • ✗

    Set up a NAT gateway in a public subnet and route traffic through it

    Why it's wrong here

    A NAT gateway provides outbound internet access, which the scenario explicitly forbids; it also cannot reach CloudWatch Logs or S3 privately. NAT gateways suit private subnets needing software updates or public API calls, not fully isolated VPCs requiring VPC endpoints.

  • ✗

    Use AWS PrivateLink to connect to CloudWatch Logs and S3

    Why it's wrong here

    S3 gateway endpoints, not PrivateLink interface endpoints, are the mechanism for private S3 access from a VPC; PrivateLink does support S3 but requires interface endpoints with per-GB charges and does not cover all S3 features. PrivateLink is correct for privately reaching services lacking gateway endpoints, such as Kinesis or EC2 APIs.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.