Courseiva

SOA-C02 Cost and Performance Optimization Practice Question

A company wants to reduce data transfer costs for traffic between EC2 instances in the same AWS Region. Which action should the SysOps administrator take?

⚠ Common exam trap

The trap is confusing cost reduction with security or availability. Also, be aware that 'same Region' does not guarantee 'same Availability Zone'; inter-AZ traffic is charged.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure instances communicate using private IP addresses within the same VPC

Traffic between EC2 instances in the same VPC using private IP addresses does not incur public internet data transfer costs. If the instances are in the same Availability Zone, the traffic is free; if they are in different Availability Zones, standard inter-AZ data transfer charges apply. Using private IPs is still the most cost-effective option compared to using public IPs (Elastic IPs) or routing through a NAT Gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Elastic IP addresses for all instances

    Why it's wrong here

    Assigning Elastic IP addresses to instances does not reduce data transfer costs; it can increase them. Elastic IPs are public IPv4 addresses, and when instance-to-instance traffic is sent over these public IPs, it routes through the internet gateway and is billed at public internet data transfer rates (typically $0.09–$0.12 per GB). Additionally, Elastic IPs themselves incur an hourly cost when not attached to a running instance, and they are not designed for intra-VPC communication — you should instead use private IPs, which have no such charges.

  • ✗

    Place instances in public subnets and route traffic through a NAT Gateway

    Why it's wrong here

    Placing instances in public subnets and routing traffic through a NAT Gateway would actively increase data transfer costs. A NAT Gateway is intended only for outbound internet access from private subnets; using it for instance-to-instance traffic would force packets to leave the VPC, incur both NAT Gateway hourly processing fees and per-GB data processing charges, and add unnecessary latency. Intra-VPC traffic between instances already traverses the internal network without needing any gateway, so routing it through a NAT Gateway is both expensive and functionally incorrect.

  • ✓

    Ensure instances communicate using private IP addresses within the same VPC

    Why this is correct

    Ensuring instances communicate using private IP addresses within the same VPC is the correct and most cost-effective approach. Traffic sent over private IPv4 addresses stays entirely inside the VPC, never crossing the internet gateway, so it is not subject to public internet data transfer rates. For instances in the same Availability Zone, this traffic is absolutely free; even across Availability Zones, the per-GB charge is only $0.01 each way, which is far cheaper than public IP or gateway-based alternatives.

  • ✗

    Use VPC endpoints to communicate between instances

    Why it's wrong here

    VPC endpoints are not a valid mechanism for reducing instance-to-instance data transfer costs. Gateway endpoints (S3, DynamoDB) and interface endpoints (other AWS services) are used exclusively to privately connect your VPC to supported AWS services, not to route traffic between EC2 instances. Using a VPC endpoint for instance communication would be architecturally unsupported, and interface endpoints additionally incur hourly charges and per-GB data processing fees, making them entirely counterproductive to the stated cost-reduction goal.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.