Publish on-premises TCP services to AWS customers through a PrivateLink endpoint service
A company has many services running in its on-premises data center. The data center is connected to AWS using AWS Direct Connect (DX) and an IPSec VPN. The service data is sensitive and connectivity cannot traverse the internet. The company wants to expand into a new market segment and begin offering its services to other companies that are using AWS. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A VPC endpoint service is fronted by a Network Load Balancer, so endpoint service consumers on AWS reach the on-premises application over the private Direct Connect path rather than the public internet.
Sensitive on-premises services must be offered to other companies that use AWS, and the traffic may not cross the internet. The existing Direct Connect and IPSec VPN path already provides private reachability into the VPC.
Trying to front the endpoint service with an Application Load Balancer. PrivateLink endpoint services require a Network Load Balancer or a Gateway Load Balancer, because the NLB operates at layer 4 and supports the TCP and TLS protocols the endpoint expects.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A VPC endpoint service backed by a Network Load Balancer publishes the on-premises service to AWS customers through PrivateLink. Because the VPC is already reachable over Direct Connect and the VPN, consumer traffic stays on the private network path, which satisfies the requirement that connectivity must not traverse the internet. An NLB is the only load balancer type that can front a VPC endpoint service.Why the Other Options Are Wrong
B: An Application Load Balancer is layer 7 only and cannot be used with a VPC endpoint service, so HTTP or HTTPS endpoint services on an ALB are not supported. C and D: An internet gateway or a NAT gateway exposes or originates traffic over the public internet, which directly violates the requirement that the data is sensitive and must not traverse the internet.Community Comment Notes
The community voted 89 to 1 for A, and the main justification was that PrivateLink endpoint services support only a Network Load Balancer or a Gateway Load Balancer, not an Application Load Balancer, and that a NAT or internet gateway path would cross the internet.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →