Troubleshooting AWS PrivateLink Endpoint Connectivity
A company's VPC has Amazon EC2 instances that are communicating with AWS services over the public internet. The company needs to change the connectivity so that the communication does not occur over the public internet. The company deploys AWS PrivateLink endpoints in the VPC. After the deployment of the PrivateLink endpoints, the EC2 instances can no longer communicate at all with the required AWS services. Which combination of steps should a network engineer take to restore communication with the AWS services? (Choose two.)
Community Votes
100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the dependency of Interface VPC Endpoints on DNS resolution; without proper DNS configuration (VPC attribute + endpoint setting), instances cannot resolve service names to private IP addresses.
When EC2 instances lose connectivity after deploying AWS PrivateLink endpoints, the issue typically stems from DNS resolution failures or restrictive endpoint policies. Community consensus confirms that enabling DNS support and verifying endpoint policies are the critical steps to restore private service access.
Candidates often select Option A, mistakenly believing that manual route table entries for PrivateLink endpoints are required. In reality, Interface Endpoints rely on DNS resolution rather than static routes, making this a common trap.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B is essential because AWS PrivateLink (Interface) endpoints rely on DNS resolution to direct traffic to the private IP addresses of the service. IfenableDnsSupport is disabled in the VPC or DNS settings are not enabled on the endpoint, the instances cannot resolve the service endpoints. Option C is also correct because even with correct DNS, the VPC Endpoint Policy acts as a filter; if it does not explicitly allow the required actions or resources, communication will be blocked.Why the Other Options Are Wrong
Option A is incorrect because Interface Endpoints do not use route table entries like Gateway Endpoints (for S3/DynamoDB); they use DNS. Option D is wrong because public hosted zones resolve to public IPs, defeating the purpose of private connectivity. Option E is unnecessary here; while private hosted zones can customize names, the default AWS-provided DNS works if configured correctly, so creating custom zones is not a primary troubleshooting step for restoring basic connectivity.Community Comment Notes
Comment [1] highlights that Option A applies only to Gateway Endpoints, not PrivateLink/Interface endpoints. Comment [2] reinforces that DNS support and endpoint policies are the two pillars of connectivity for this scenario. Comment [3] correctly identifies that Route 53 hosted zones are not strictly required to restore functionality if standard DNS resolution is fixed.Official Reference
Exam Strategy
Always distinguish between Gateway Endpoints (S3/DynamoDB, which use route tables) and Interface Endpoints (PrivateLink, which use DNS). When troubleshooting Interface Endpoints, check DNS resolution capabilities and security policies first.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →