Courseiva

SOA-C02 VPC Gateway Endpoint Practice Question

A SysOps administrator needs to reduce data transfer costs for a web application hosted on EC2 instances in a VPC. The application serves content to users over the internet. Which TWO actions will help reduce data transfer costs? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a VPC Gateway Endpoint for Amazon S3 to keep S3 traffic within AWS.

Option B is correct because a VPC Gateway Endpoint for Amazon S3 routes S3 traffic privately within the AWS network instead of through a NAT Gateway or internet gateway, eliminating NAT data processing charges and internet data transfer fees for that traffic. Option C is correct because Amazon CloudFront caches static content at edge locations closer to users, reducing the volume of data transferred out from the EC2 instances and lowering EC2 data transfer out charges. Option A is incorrect because Direct Connect is for private connectivity to AWS, not for serving public internet users, and private subnets do not reduce internet egress costs. Option D is incorrect because an Application Load Balancer distributes traffic but does not by itself reduce data transfer costs and adds LCU charges. Option E is incorrect because a larger NAT Gateway does not lower per-GB NAT data processing charges and may increase cost.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Move all instances to private subnets and use AWS Direct Connect for user access.

    Why it's wrong here

    Direct Connect links your on-premises network to AWS and is not a path for public internet users; moving instances to private subnets would also require a public entry point. It is tempting because Direct Connect reduces egress charges for hybrid traffic, but it cannot serve the application's internet audience.

  • ✓

    Use a VPC Gateway Endpoint for Amazon S3 to keep S3 traffic within AWS.

    Why this is correct

    A VPC gateway endpoint routes S3 traffic privately within the AWS network instead of through a NAT gateway or internet gateway, eliminating NAT data processing charges and internet data transfer for that traffic. This directly cuts the transfer costs the stem asks to reduce.

  • ✓

    Use Amazon CloudFront to cache and serve static content.

    Why this is correct

    CloudFront caches static content at edge locations and serves users from the nearest point of presence, so fewer requests travel back to the EC2 origin. This reduces origin data transfer out, which is the dominant cost driver for internet-facing content.

  • ✗

    Use an Application Load Balancer to distribute traffic.

    Why it's wrong here

    An Application Load Balancer distributes incoming traffic but does not reduce the volume of data transferred out to internet users, which is what drives the cost. It is tempting because ALBs improve availability and can terminate TLS, yet data transfer charges accrue per gigabyte leaving AWS regardless of load balancing.

  • ✗

    Use a larger NAT Gateway to improve throughput.

    Why it's wrong here

    NAT Gateway capacity is not a size setting; you cannot select a larger one, and it charges per gigabyte processed plus hourly, so it adds cost rather than reducing it. It is tempting because NAT Gateways handle outbound traffic, but they are for private subnet egress, not for serving internet users.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.