exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 144 discussion

Exam question from Amazon's ANS-C00
Question #: 144
Topic #: 1
[All ANS-C00 Questions]

You are responsible for several EC2 instances deployed from Amazon AMIs that are required to upload information to an S3 bucket. This information must not traverse the public internet. You must also be able to update the instances. Which option is your best solution?

  • A. An S3 endpoint and a NAT
  • B. An S3 endpoint
  • C. A VPN to the IP addresses specified in the AWS official S3 prefix list
  • D. A NACL with the AWS prefix list added to it and a VPN.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BlueGreen
Highly Voted 3 years, 7 months ago
A This information must not traverse the public internet. upload information to an S3 bucket. ----> S3 endpoint You must also be able to update the instances. -------> NAT
upvoted 20 times
...
squeeze_talus0y
Most Recent 2 years, 6 months ago
Selected Answer: A
We don't know what AMI is being used. Even with AL2 AMI the EC2s might need to use EPEL repo.
upvoted 1 times
...
nklocal
2 years, 8 months ago
Answer is A, for Internet access to update and for S3 Access to use endpoint
upvoted 1 times
...
Marty2021
2 years, 10 months ago
Selected Answer: B
Having read the link sapien45 posted and the question mentions Amazon AMIs it looks to me like the best answer is B, its simpler, doesn't incur cost of NAT gateway.
upvoted 1 times
slackbot
2 years, 1 month ago
third-party repos (like EPEL) require internet access. So - best bet is A
upvoted 1 times
...
...
jerac58653
2 years, 11 months ago
Selected Answer: A
Because the instances need to be updated via Internet.
upvoted 2 times
...
Derrick888
2 years, 11 months ago
Selected Answer: B
B is correct, no need internet access for yum update on amazon linux. all go thru AWS internal repos.
upvoted 1 times
...
RenatoFonseca
3 years ago
Selected Answer: A
The EC2 Instances need to be updated using NAT Gateway.
upvoted 1 times
...
sapien45
3 years, 2 months ago
B it is. Verify that your EC2 instance has access to Amazon Linux repositories using one of the following options Your instance is in a public or private subnet with an S3 VPC endpoint https://aws.amazon.com/premiumsupport/knowledge-center/ec2-troubleshoot-yum-errors-al1-al2/
upvoted 2 times
...
ktulu2602
3 years, 2 months ago
Selected Answer: B
I agree with mark_232323 - B
upvoted 2 times
...
mark_232323
3 years, 3 months ago
Answer is B, Amazon Linux repositories are hosted in Amazon Simple Storage Service (Amazon S3) buckets. To update and install packages on your instance without an internet connection, create an S3 Amazon Virtual Private Cloud (Amazon VPC) gateway endpoint. In the S3 VPC gateway endpoint, include a policy that allows access to the repositories buckets. Then, associate the VPC endpoint with the routing table of your instance subnet. https://aws.amazon.com/premiumsupport/knowledge-center/ec2-al1-al2-update-yum-without-internet/
upvoted 3 times
...
2shyshy
3 years, 3 months ago
A would be the answer, you need the S3 endpoint to communicate internally to S3, but you need the NAT to update the instances to the Internet.
upvoted 1 times
...
Cyril_the_Squirl
3 years, 6 months ago
A is Correct. 2 Things you MUST make possible... A=Upload to S3 without traversing the internet...S3 Endpoint. B=Must be able to update your EC2, this means you require Internet Access..therefore NAT. Your EC2 instance could be a Windows machine, Linux or anything at all, you will simply need internet access. S3 endpoint is not magically going to give you ability to do windows updates, neither are there lunux repos in the s3 infrastructure!
upvoted 3 times
...
ptpho
3 years, 6 months ago
My ans is B. If you uploaded info to S3 then you only need to change your repo params to select source from S3. We dont need NAT and Internet cnx at all
upvoted 1 times
...
dev62
3 years, 6 months ago
I think A is correct, as there are 2 things, 1. This (S3) information must not traverse the public internet. --> S3 endpoint 2. You must also be able to update the instances --> NAT
upvoted 1 times
...
ChauPhan
3 years, 7 months ago
S3 endpoint and PrivateLink, not NAT
upvoted 1 times
ChauPhan
3 years, 6 months ago
An S3 endpoint and a NAT
upvoted 1 times
...
...
Huntkey
3 years, 7 months ago
I agree with ArekD. B is more likely to be the correct answer
upvoted 1 times
...
smithyt
3 years, 7 months ago
If you using a Nat you are traversing the Internet, where the endpoint uses AWS backbone
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago