nerdexam
Amazon

ANS-C01 · Question #4

A global delivery company is modernizing its fleet management system. The company has several business units. Each business unit designs and maintains applications that are hosted in its own AWS…

The correct answer is C. Create VPC endpoint services powered by AWS PrivateLink in the central shared services. Option C provides a secure and scalable solution using VPC endpoint services powered by AWS PrivateLink. AWS PrivateLink enables private connectivity between VPCs and services without exposing the data to the public internet or using a VPN connection. By creating VPC endpoints…

Submitted by valeria.br· Mar 6, 2026Network Design

Question

A global delivery company is modernizing its fleet management system. The company has several business units. Each business unit designs and maintains applications that are hosted in its own AWS account in separate application VPCs in the same AWS Region. Each business unit's applications are designed to get data from a central shared services VPC. The company wants the network connectivity architecture to provide granular security controls. The architecture also must be able to scale as more business units consume data from the central shared services VPC in the future. Which solution will meet these requirements in the MOST secure manner?

Options

  • ACreate a central transit gateway. Create a VPC attachment to each application VPC. Provide full
  • BCreate VPC peering connections between the central shared services VPC and each application
  • CCreate VPC endpoint services powered by AWS PrivateLink in the central shared services
  • DCreate a central transit VPC with a VPN appliance from AWS Marketplace. Create a VPN

How the community answered

(41 responses)
  • A
    10% (4)
  • B
    5% (2)
  • C
    66% (27)
  • D
    20% (8)

Explanation

Option C provides a secure and scalable solution using VPC endpoint services powered by AWS PrivateLink. AWS PrivateLink enables private connectivity between VPCs and services without exposing the data to the public internet or using a VPN connection. By creating VPC endpoints in each application VPC, the company can securely access the central shared services VPC without the need for complex network configurations. Furthermore, PrivateLink supports cross-account connectivity, which makes it a scalable solution as more business units consume data from the central shared services VPC in the future.

Topics

#AWS PrivateLink#VPC Endpoint Service#Multi-account networking#Network security

Community Discussion

No community discussion yet for this question.

Full ANS-C01 Practice