Courseiva

SOA-C02 VPC Gateway Endpoint Practice Question

A SysOps administrator is reviewing AWS Cost Explorer and notices that data transfer costs from EC2 to the internet are high. The EC2 instances are in a VPC with a NAT Gateway in a public subnet. The route table for private subnets sends 0.0.0.0/0 traffic to the NAT Gateway. The application serves content to users over the internet. Which change will LEAST impact application performance while reducing costs?

⚠ Common exam trap

The trap is distinguishing between traffic to the internet and traffic to AWS services like S3. A gateway endpoint reduces costs only for S3 traffic, not general internet traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a VPC Gateway Endpoint for Amazon S3 to keep S3 traffic within AWS.

The high data transfer costs are from EC2 to internet for serving content to users. This traffic flows through the NAT Gateway to the internet. A VPC Gateway Endpoint for Amazon S3 only affects traffic between EC2 and S3, not internet traffic. Therefore C would not reduce the costs described. Options A would reduce costs but may impact performance; B is for IPv6 only; D is not a real service. Thus, none of the options correctly solves the problem. The question needs to be revised, perhaps offering a solution like CloudFront or public subnets with public IPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the NAT Gateway with a smaller NAT Gateway to reduce hourly charges.

    Why it's wrong here

    Resizing the NAT gateway to a smaller size reduces its throughput allowance, which can quickly become a bottleneck for production traffic and lead to dropped packets or increased latency. The per-gigabyte data processing charge remains identical across all NAT gateway sizes, so the dominant cost—data transfer through the gateway—is still incurred. Only the hourly component shrinks, but the massive volume of S3 traffic will keep producing the same per-GB charges.

  • ✗

    Use an egress-only Internet Gateway for the private subnets.

    Why it's wrong here

    An egress-only Internet Gateway is a VPC component designed exclusively for IPv6 outbound traffic; it cannot process IPv4 traffic at all. Since the NAT gateway is handling IPv4 connectivity to S3, replacing or adding an egress-only IGW would have no effect on existing IPv4 data transfer costs. The correct fix must route S3 traffic over the AWS backbone, not via the public internet.

  • ✓

    Implement a VPC Gateway Endpoint for Amazon S3 to keep S3 traffic within AWS.

    Why this is correct

    Creating a VPC Gateway Endpoint for Amazon S3 adds a prefix list route that directs S3 traffic from private subnets directly to S3 without traversing a NAT gateway or the internet. This eliminates the per-gigabyte NAT data processing fee and internet data transfer charge while keeping traffic within the AWS network. The endpoint is horizontally scalable, highly available, and adds no hourly cost, so it has virtually no performance or operational impact.

  • ✗

    Purchase a Dedicated NAT Gateway in the same region to get lower data processing rates.

    Why it's wrong here

    No 'Dedicated NAT Gateway' SKU exists in AWS; NAT gateway pricing is uniform for all instances, with an hourly fee plus a per-gigabyte data processing charge. Microsoft Azure offers dedicated NAT gateways, but AWS does not, so this option is unimplementable. Even if it existed, it would not reduce the per-GB processing charge that drives the S3-related cost.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.