How to Expose a Private ALB-Backed Service to Approved AWS Accounts with Least Overhead?

A company has developed a web service for language translation. The web service's application runs on a fleet of Amazon EC2 instances that are in an Auto Scaling group. The instances run behind an Application Load Balancer (ALB) and are deployed in a private subnet. The web service can process requests that contain hundreds of megabytes of data. The company needs to give some customers the ability to access the web service. Each customer has its own AWS account. The company must make the web service accessible to approved customers without making the web service accessible to all customers. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)

  1. Create VPC peering connections with the approved customers only.
  2. Create an AWS PrivateLink endpoint service. Configure the endpoint service to require acceptance that will be granted to approved customers only. Source Reference Answer
  3. Configure an authentication action for the endpoint service's load balancer to allow customers to log in by using their AWS credentials. Provide only approved customers with the URL.
  4. Configure a Network Load Balancer (NLB) and a listener with the ALB as a target. Associate the NLB with the endpoint service. Source Reference Answer
  5. Associate the ALB with the endpoint service.

Community Votes

BD
100%

100% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your understanding of AWS PrivateLink architecture and the fact that endpoint services require an NLB (or Gateway Load Balancer) as the service resource, not an ALB directly.

The correct combination is B and D: use an AWS PrivateLink endpoint service with acceptance required and a Network Load Balancer (NLB) fronting the Application Load Balancer. This provides secure, fine-grained access for approved customer accounts with minimal operational overhead.

A common mistake is selecting E (associate the ALB directly with the endpoint service) because ALB is not a supported service resource for AWS PrivateLink; you must use an NLB as the front-end. Another mistake is choosing A (VPC peering) because peering opens access to entire VPCs and requires complex route management, increasing overhead and security risk.

Community Discussion (3 comments)

AzureDP900 👍 3
B and D Both options provide a secure connection between your EC2 instances behind an ALB and approved customers' AWS accounts, ensuring that only authorized users have access to your web service.
cas_tori 👍 1 Selected: BD
this is BD
rdiaz 👍 3 Selected: BD
BD are ok

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B creates an AWS PrivateLink endpoint service and configures it to require acceptance, which ensures that only approved customer principals can receive an interface endpoint. Option D correctly configures an NLB with the ALB as a target, because AWS PrivateLink endpoint services are backed by an NLB (or Gateway Load Balancer), and the ALB behind it handles the application-layer translation workload. Together, these steps provide a secure, managed, and least-overhead solution for exposing the private web service to selected customers.

Why the Other Options Are Wrong

Option A (VPC peering) is not least overhead because it requires managing peering connections, route tables, and security groups for each customer, and it gives broad network-level access to the entire VPC rather than a controlled service endpoint. Option C is misleading because the authentication action on an ALB is for user login (e.g., OIDC or Cognito), not for granting AWS-account-level access to a PrivateLink service; providing a URL alone does not restrict access to approved customers. Option E is invalid because an ALB cannot be directly attached to a PrivateLink endpoint service; AWS requires an NLB or Gateway Load Balancer as the service provider resource.

Community Comment Notes

Community comments uniformly agree on BD, with one comment noting that both options provide a secure connection between the EC2 instances behind the ALB and approved customer accounts. Another comment succinctly states "BD are ok," reinforcing the consensus. No community comment suggests alternative answers, and the provided explanation highlights that the architecture must use an NLB to terminate the PrivateLink connection and forward traffic to the ALB.

Official Reference

Exam Strategy

On ANS-C01, remember that PrivateLink endpoint services require an NLB (or Gateway Load Balancer) as the service resource. When you see a question about exposing an ALB-backed service to specific accounts, immediately think B (endpoint service with acceptance required) and D (NLB in front of the ALB), not VPC peering or direct ALB association.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide