Troubleshooting AWS PrivateLink Endpoint Connectivity

A company's VPC has Amazon EC2 instances that are communicating with AWS services over the public internet. The company needs to change the connectivity so that the communication does not occur over the public internet. The company deploys AWS PrivateLink endpoints in the VPC. After the deployment of the PrivateLink endpoints, the EC2 instances can no longer communicate at all with the required AWS services. Which combination of steps should a network engineer take to restore communication with the AWS services? (Choose two.)

  1. In the VPC route table, add a route that has the PrivateLink endpoints as the destination.
  2. Ensure that the enableDnsSupport attribute is set to True for the VPC. Ensure that each VPC endpoint has DNS support enabled. Source Reference Answer
  3. Ensure that the VPC endpoint policy allows communication. Source Reference Answer
  4. Create an Amazon Route 53 public hosted zone for all services.
  5. Create an Amazon Route 53 private hosted zone that includes a custom name for each service.

Community Votes

BC
100%

100% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the dependency of Interface VPC Endpoints on DNS resolution; without proper DNS configuration (VPC attribute + endpoint setting), instances cannot resolve service names to private IP addresses.

When EC2 instances lose connectivity after deploying AWS PrivateLink endpoints, the issue typically stems from DNS resolution failures or restrictive endpoint policies. Community consensus confirms that enabling DNS support and verifying endpoint policies are the critical steps to restore private service access.

Candidates often select Option A, mistakenly believing that manual route table entries for PrivateLink endpoints are required. In reality, Interface Endpoints rely on DNS resolution rather than static routes, making this a common trap.

Community Discussion (3 comments)

woorkim 👍 1 Selected: BC
A is incorrect: Adding routes to the PrivateLink endpoints in the route table is not necessary for endpoint communication D is incorrect: Creating a public hosted zone is not the right approach for private connectivity E is incorrect: While private hosted zones can be useful, they are not directly required to restore PrivateLink endpoint communication
Akshay0403 👍 2 Selected: BC
The most effective steps are B and C. Ensuring that DNS support is enabled for both the VPC and the PrivateLink endpoints, along with verifying that the VPC endpoint policy permits the required access, will restore the necessary communication between the EC2 instances and the AWS services over the private network. These steps ensure that the services are correctly resolved and accessible while maintaining security and privacy through the AWS network.
seochan 👍 3 Selected: BC
A. This is not a VPC Gateway Endpoint. B. You need to use AmazonProvidedDNS, so this is doable option. C. VPC endpoint policy might block the connection, so possible cause. D & E. You don't need to use the R53 Hosted Zone for this scenario.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is essential because AWS PrivateLink (Interface) endpoints rely on DNS resolution to direct traffic to the private IP addresses of the service. If enableDnsSupport is disabled in the VPC or DNS settings are not enabled on the endpoint, the instances cannot resolve the service endpoints. Option C is also correct because even with correct DNS, the VPC Endpoint Policy acts as a filter; if it does not explicitly allow the required actions or resources, communication will be blocked.

Why the Other Options Are Wrong

Option A is incorrect because Interface Endpoints do not use route table entries like Gateway Endpoints (for S3/DynamoDB); they use DNS. Option D is wrong because public hosted zones resolve to public IPs, defeating the purpose of private connectivity. Option E is unnecessary here; while private hosted zones can customize names, the default AWS-provided DNS works if configured correctly, so creating custom zones is not a primary troubleshooting step for restoring basic connectivity.

Community Comment Notes

Comment [1] highlights that Option A applies only to Gateway Endpoints, not PrivateLink/Interface endpoints. Comment [2] reinforces that DNS support and endpoint policies are the two pillars of connectivity for this scenario. Comment [3] correctly identifies that Route 53 hosted zones are not strictly required to restore functionality if standard DNS resolution is fixed.

Official Reference

Exam Strategy

Always distinguish between Gateway Endpoints (S3/DynamoDB, which use route tables) and Interface Endpoints (PrivateLink, which use DNS). When troubleshooting Interface Endpoints, check DNS resolution capabilities and security policies first.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide