Question 1 · choose 1
An application runs on Amazon EC2 instances in private subnets with no internet access. Security policy says its calls to Amazon Bedrock must not travel over the internet and the instances must not get public IP addresses. What should the team set up?
- AA NAT gateway in a public subnet for the private subnets to use
- BAn interface VPC endpoint for Amazon Bedrock, powered by AWS PrivateLink
- CAn Elastic IP address attached to each instance
- DAn Amazon CloudFront distribution placed in front of the Amazon Bedrock API endpoint
Show the answer and why
AA NAT gateway in a public subnet for the private subnets to use
Incorrect
A public NAT gateway lets private instances connect to services outside the VPC through an internet gateway. The Bedrock interface endpoint is reached without an internet gateway or NAT device.
BAn interface VPC endpoint for Amazon Bedrock, powered by AWS PrivateLink
Correct
An interface endpoint creates a private connection between the VPC and Amazon Bedrock, without an internet gateway, NAT device or VPN, and instances need no public IP addresses.
CAn Elastic IP address attached to each instance
Incorrect
Public addresses are exactly what the policy rules out, and with an interface endpoint, instances do not need public IP addresses to reach Amazon Bedrock.
DAn Amazon CloudFront distribution placed in front of the Amazon Bedrock API endpoint
Incorrect
CloudFront speeds up the distribution of web content to users. It does not provide private connectivity from a VPC to an AWS service.
Private access to an AWS service from a VPC is the job of an interface VPC endpoint (AWS PrivateLink); traffic then stays off the internet.
AWS documentation