SOA-C02 Networking and Content Delivery Practice Question
A company runs an application on Amazon EC2 instances in private subnets of a VPC. The application needs to upload files to an Amazon S3 bucket in the same AWS Region. The SysOps administrator wants to ensure that traffic to S3 does not traverse the internet and minimizes data transfer costs. Which solution should the administrator implement?
⚠ Common exam trap
Many exam-takers confuse Gateway Endpoints with Interface Endpoints, assuming Interface Endpoints are always better because they use security groups, but for S3, Gateway Endpoints are free and more cost-effective, while Interface Endpoints incur additional charges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an S3 Gateway Endpoint and add a route in the private subnet route table pointing to it.
An S3 Gateway Endpoint is the correct solution because it provides private connectivity from a VPC to S3 without traversing the internet, using AWS's internal network. By adding a route in the private subnet's route table pointing to the gateway endpoint, traffic to S3 stays within the AWS backbone, minimizing data transfer costs (no NAT gateway charges) and avoiding internet egress fees.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a NAT gateway in a public subnet and route private subnet traffic to it.
Why it's wrong here
Although a NAT gateway in a public subnet can provide outbound internet access, it would force S3 traffic to traverse the internet gateway, breaking the private connectivity assumption and incurring NAT gateway hourly charges plus data transfer costs for every object retrieval or upload. NAT gateways are also AZ-scoped and require one per AZ for high availability, adding even more cost and complexity. This solution fails the 'fully private and cost-effective' requirement because the traffic is not contained within the AWS network.
- ✓
Create an S3 Gateway Endpoint and add a route in the private subnet route table pointing to it.
Why this is correct
An S3 Gateway Endpoint is a free, highly available gateway object attached to a VPC that uses a prefix list to route S3 traffic from a private subnet without going over the internet. You must add a route in the private subnet's route table with the destination as the S3 prefix list and the target as the gateway endpoint; traffic stays entirely inside the AWS network. This is the recommended pattern for private subnets because it requires no NAT gateway, no IGW, and no data transfer charges.
- ✗
Create an S3 Interface Endpoint and assign a security group.
Why it's wrong here
An S3 Interface Endpoint creates a private ENI with an IP address in your subnet and is backed by AWS PrivateLink, but it is metered per hour and per gigabyte of data processed, making it significantly more expensive than a Gateway Endpoint for high-volume S3 access. It also requires a security group to control access, adding management overhead that a Gateway Endpoint does not require. For a simple private-subnet-to-S3 connection, this is over-engineered and costlier than necessary.
- ✗
Use AWS PrivateLink to connect to S3.
Why it's wrong here
AWS PrivateLink is the underlying service that enables interface endpoints, so using PrivateLink to connect to S3 is effectively the same as deploying an interface endpoint. This approach incurs hourly endpoint charges and per-GB data processing fees, and it requires additional configuration such as security groups and endpoint policies. Because S3 supports Gateway Endpoints, which are free and purely private, using PrivateLink is an unnecessarily expensive and complex alternative for this scenario.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.