Courseiva

SOA-C02 Cost and Performance Optimization Practice Question

A SysOps administrator is reviewing the monthly AWS bill and notices a significant cost for data transfer from EC2 to the internet. The EC2 instances are in a VPC and serve content to users. Which action would MOST effectively reduce data transfer costs?

⚠ Common exam trap

The trap is confusing VPC endpoints with CDNs. VPC endpoints reduce costs for private traffic to AWS services, not for internet-facing traffic. Candidates might also think NAT Gateway reduces costs, but it actually adds data processing charges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon CloudFront as a content delivery network (CDN).

Using Amazon CloudFront as a CDN caches content at edge locations closer to users, reducing the amount of data transferred directly from EC2 instances to the internet. This lowers data transfer out (DTO) costs because CloudFront has lower data transfer rates and can also cache content, reducing the load on EC2. The question specifies data transfer from EC2 to the internet, so offloading to CloudFront is the most effective cost reduction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use VPC endpoints to connect to S3 and DynamoDB.

    Why it's wrong here

    VPC endpoints enable private connections between your VPC and AWS services like S3 and DynamoDB, bypassing the public internet and eliminating data transfer charges for those API calls that would otherwise traverse a NAT gateway or Internet gateway. However, they do not affect the dominant cost driver on an EC2 bill: egress traffic to end users on the internet. Because the monthly bill likely reflects general internet data transfer, VPC endpoints address only a narrow traffic subset and leave the main charges untouched.

  • ✓

    Use Amazon CloudFront as a content delivery network (CDN).

    Why this is correct

    Amazon CloudFront serves as a content delivery network, caching responses at edge locations so repeat requests never reach the EC2 origin. This reduces the volume of data transferred directly from EC2 to the public internet and, for requests that do go to the origin, the AWS-to-CloudFront leg is free while CloudFront's egress rate is lower than EC2's standard internet data transfer rate. Offloading delivery to edge servers therefore both cuts total egress gigabytes and shifts remaining traffic to a cheaper pricing tier, directly lowering the monthly bill.

  • ✗

    Move the EC2 instances to a different AWS Region with lower data transfer rates.

    Why it's wrong here

    AWS prices internet data transfer from EC2 on a per-GB basis that is consistent across most commercial AWS Regions; any regional differences are minor and rarely justify the cost, risk, and operational effort of migrating live instances. Moving regions also introduces latency changes, data residency considerations, and requires re-adapting dependent services like VPC peering and security groups. Consequently, choosing a different region does not meaningfully reduce data transfer spend and often creates collateral disruption instead.

  • ✗

    Use a NAT Gateway to route traffic through a single IP.

    Why it's wrong here

    A NAT gateway offers outbound internet access from private subnets through a single Elastic IP, but it is metered by both hourly usage and per-GB data processing fees. Rather than reducing data transfer costs, it adds an additional charge on top of the traffic it forwards, so your bill would increase for the same workload. Furthermore, NAT gateways only manage outbound connections; they do not influence the inbound egress traffic from EC2 to users that forms the bulk of typical data transfer expenses.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.