Question 1 · choose 1
In the design of a new data platform, EC2 instances in private subnets will read about 300 TB per month from Amazon S3 and write results to Amazon DynamoDB, both in the same Region. The draft sends this traffic through NAT gateways. The data must not travel over the internet. Which change gives the largest cost reduction?
- AReplace the NAT gateways with NAT instances on large EC2 instance types
- BAdd gateway VPC endpoints for Amazon S3 and DynamoDB to the route tables of the private subnets
- CAdd interface VPC endpoints for Amazon S3 and DynamoDB in each Availability Zone
- DMove the instances to public subnets with public IP addresses and reach the services through an internet gateway
Show the answer and why
AReplace the NAT gateways with NAT instances on large EC2 instance types
Incorrect
NAT instances remove the NAT gateway charges but add instance costs and management, and the traffic would still pass through a NAT device.
BAdd gateway VPC endpoints for Amazon S3 and DynamoDB to the route tables of the private subnets
Correct
Gateway endpoints for S3 and DynamoDB carry the traffic privately from the VPC and have no additional charge, so the NAT gateway data processing charges for this traffic disappear.
CAdd interface VPC endpoints for Amazon S3 and DynamoDB in each Availability Zone
Incorrect
Interface endpoints are billed per hour and per GB processed, so they cost more than gateway endpoints for the same traffic.
DMove the instances to public subnets with public IP addresses and reach the services through an internet gateway
Incorrect
This removes the NAT charges but exposes the instances, and the requirement that data does not use the internet path would no longer be met.
For S3 and DynamoDB in the same Region, gateway endpoints are both the private path and the cheapest one.
AWS documentation