How to Expose a Private ALB-Backed Service to Approved AWS Accounts with Least Overhead?
A company has developed a web service for language translation. The web service's application runs on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The instances run behind an Application Load Balancer (ALB) and are deployed in a private subnet. The web service can process requests that contain hundreds of megabytes of data. The company needs to give some customers the ability to access the web service. Each customer has its own AWS account. The company must make the web service accessible to approved customers without making the web service accessible to all customers. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
Community Votes
100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of AWS PrivateLink architecture and the fact that endpoint services require an NLB (or Gateway Load Balancer) as the service resource, not an ALB directly.
The correct combination is B and D: use an AWS PrivateLink endpoint service with acceptance required and a Network Load Balancer (NLB) fronting the Application Load Balancer. This provides secure, fine-grained access for approved customer accounts with minimal operational overhead.
A common mistake is selecting E (associate the ALB directly with the endpoint service) because ALB is not a supported service resource for AWS PrivateLink; you must use an NLB as the front-end. Another mistake is choosing A (VPC peering) because peering opens access to entire VPCs and requires complex route management, increasing overhead and security risk.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B creates an AWS PrivateLink endpoint service and configures it to require acceptance, which ensures that only approved customer principals can receive an interface endpoint. Option D correctly configures an NLB with the ALB as a target, because AWS PrivateLink endpoint services are backed by an NLB (or Gateway Load Balancer), and the ALB behind it handles the application-layer translation workload. Together, these steps provide a secure, managed, and least-overhead solution for exposing the private web service to selected customers.
Why the Other Options Are Wrong
Option A (VPC peering) is not least overhead because it requires managing peering connections, route tables, and security groups for each customer, and it gives broad network-level access to the entire VPC rather than a controlled service endpoint. Option C is misleading because the authentication action on an ALB is for user login (e.g., OIDC or Cognito), not for granting AWS-account-level access to a PrivateLink service; providing a URL alone does not restrict access to approved customers. Option E is invalid because an ALB cannot be directly attached to a PrivateLink endpoint service; AWS requires an NLB or Gateway Load Balancer as the service provider resource.
Community Comment Notes
Community comments uniformly agree on BD, with one comment noting that both options provide a secure connection between the EC2 instances behind the ALB and approved customer accounts. Another comment succinctly states "BD are ok," reinforcing the consensus. No community comment suggests alternative answers, and the provided explanation highlights that the architecture must use an NLB to terminate the PrivateLink connection and forward traffic to the ALB.
Official Reference
Exam Strategy
On ANS-C01, remember that PrivateLink endpoint services require an NLB (or Gateway Load Balancer) as the service resource. When you see a question about exposing an ALB-backed service to specific accounts, immediately think B (endpoint service with acceptance required) and D (NLB in front of the ALB), not VPC peering or direct ALB association.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →