exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 218 discussion

A company is running an application in the AWS Cloud. The application consists of microservices that run on a fleet of Amazon EC2 instances in multiple Availability Zones behind an Application Load Balancer. The company recently added a new REST API that was implemented in Amazon API Gateway. Some of the older microservices that run on EC2 instances need to call this new API.

The company does not want the API to be accessible from the public internet and does not want proprietary data to traverse the public internet.

What should a solutions architect do to meet these requirements?

  • A. Create an AWS Site-to-Site VPN connection between the VPC and the API Gateway. Use API Gateway to generate a unique API Key for each microservice. Configure the API methods to require the key.
  • B. Create an interface VPC endpoint for API Gateway, and set an endpoint policy to only allow access to the specific API. Add a resource policy to API Gateway to only allow access from the VPC endpoint. Change the API Gateway endpoint type to private.
  • C. Modify the API Gateway to use IAM authentication. Update the IAM policy for the IAM role that is assigned to the EC2 instances to allow access to the API Gateway. Move the API Gateway into a new VPDeploy a transit gateway and connect the VPCs.
  • D. Create an accelerator in AWS Global Accelerator, and connect the accelerator to the API Gateway. Update the route table for all VPC subnets with a route to the created Global Accelerator endpoint IP address. Add an API key for each service to use for authentication.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SkyZeroZx
Highly Voted 10 months ago
Selected Answer: B
Tip: Anytime you see "don't want to traverse Internet traffic" always look for endpoint in the answers. Most likely, that's the answer.
upvoted 11 times
...
Just_Ninja
Highly Voted 9 months, 1 week ago
Selected Answer: B
The quality control here is unfortunately not as expected when you buy access. C is due nonsense. B is correct. VPC Endpoint to API Gateway and a policy on both sides! Trust me, i´m a Ninja
upvoted 6 times
rxhan
9 months ago
thanks Ninja
upvoted 2 times
...
...
shaaam80
Most Recent 4 months, 4 weeks ago
Selected Answer: B
Answer B - VPC Interface endpoint to privately access services without data over internet.
upvoted 3 times
...
career360guru
5 months ago
Selected Answer: B
Option B
upvoted 1 times
...
NikkyDicky
9 months, 3 weeks ago
Selected Answer: B
B for sure
upvoted 1 times
...
Alabi
10 months, 1 week ago
Selected Answer: B
B for sure
upvoted 1 times
...
SmileyCloud
10 months, 1 week ago
Selected Answer: B
Tip: Anytime you see "don't want to traverse Internet traffic" always look for endpoint in the answers. Most likely, that's the answer.
upvoted 3 times
...
easytoo
10 months, 1 week ago
b-b-b-b-b-b-b By implementing this solution, the company can ensure that the new API in API Gateway is not accessible from the public internet. The interface VPC endpoint provides private connectivity, allowing secure communication between the microservices running on EC2 instances and the API Gateway. This ensures the proprietary data does not traverse the public internet, enhancing security and data protection.
upvoted 3 times
...
bhanus
10 months, 1 week ago
I vote B
upvoted 1 times
...
nexus2020
10 months, 1 week ago
Selected Answer: B
VPC endpoint usualy is the prefect answer to avoid internet traffic
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago