Question 1 · choose 2
EC2 instances in private subnets send about 80 TB per month to Amazon S3 and 20 TB per month to Amazon DynamoDB in the same Region, all through a NAT gateway. The NAT gateway's data processing charges are the largest item on the network bill. Which changes reduce these costs the most? (Choose TWO.)
- AAdd a gateway VPC endpoint for Amazon S3 to the private route tables
- BCreate an interface VPC endpoint for Amazon S3 in each Availability Zone
- CMove the NAT gateway to a public subnet in another Availability Zone
- DAdd a gateway VPC endpoint for DynamoDB to the private route tables
- ETurn on S3 Transfer Acceleration for the buckets the instances use
Show the answer and why
AAdd a gateway VPC endpoint for Amazon S3 to the private route tables
Correct
Gateway endpoints reach S3 without a NAT device and carry no additional charge, so the S3 traffic leaves the NAT gateway's bill.
BCreate an interface VPC endpoint for Amazon S3 in each Availability Zone
Incorrect
It also bypasses the NAT gateway, but interface endpoints are charged per hour in each zone and per GB processed, unlike gateway endpoints.
CMove the NAT gateway to a public subnet in another Availability Zone
Incorrect
Sending traffic to a NAT gateway in another zone adds cross-zone data transfer charges on top of the processing charges.
DAdd a gateway VPC endpoint for DynamoDB to the private route tables
Correct
DynamoDB also supports gateway endpoints at no additional charge, so its traffic stops passing through the NAT gateway.
ETurn on S3 Transfer Acceleration for the buckets the instances use
Incorrect
Transfer Acceleration can add charges and the traffic would still go through the NAT gateway.
Traffic to S3 and DynamoDB does not need a NAT gateway at all. Gateway endpoints remove it from the NAT path at no extra charge.
AWS documentation