Publish on-premises TCP services to AWS customers through a PrivateLink endpoint service

Answer Correct answer: A — Create a VPC endpoint service for TCP traffic behind a Network Load Balancer and make it reachable over Direct Connect.

A company has many services running in its on-premises data center. The data center is connected to AWS using AWS Direct Connect (DX) and an IPSec VPN. The service data is sensitive and connectivity cannot traverse the internet. The company wants to expand into a new market segment and begin offering its services to other companies that are using AWS. Which solution will meet these requirements?

  1. Create a VPC Endpoint Service that accepts TCP traffic, host it behind a Network Load Balancer, and make the service available over DX. Correct Answer
  2. Create a VPC Endpoint Service that accepts HTTP or HTTPS traffic, host it behind an Application Load Balancer, and make the service available over DX.
  3. Attach an internet gateway to the VPC, and ensure that network access control and security group rules allow the relevant inbound and outbound traffic.
  4. Attach a NAT gateway to the VPC, and ensure that network access control and security group rules allow the relevant inbound and outbound traffic.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A VPC endpoint service is fronted by a Network Load Balancer, so endpoint service consumers on AWS reach the on-premises application over the private Direct Connect path rather than the public internet.

Sensitive on-premises services must be offered to other companies that use AWS, and the traffic may not cross the internet. The existing Direct Connect and IPSec VPN path already provides private reachability into the VPC.

Trying to front the endpoint service with an Application Load Balancer. PrivateLink endpoint services require a Network Load Balancer or a Gateway Load Balancer, because the NLB operates at layer 4 and supports the TCP and TLS protocols the endpoint expects.

Community Discussion (11 comments)

backbencher2022 👍 3 Selected: A
A is the correct option. There is no direct support for ALB with Private Link / VPC Endpoint service. ALB can be a target group for NLB so, we can use ALB with NLB but not ALB directly. Check this page for more details - https://aws.amazon.com/about-aws/whats-new/2021/09/application-load-balancer-aws-privatelink-static-ip-addresses-network-load-balancer/
asquared16 👍 2
What do we know that makes B not a valid answer? It feels like the question is missing something.
gfhbox0083 👍 2
A, for sure. Connectivity cannot traverse the internet
trungtd 👍 2 Selected: A
A, VPC endpoint used with NLB
VerRi 👍 2 Selected: A
VPC endpoint + NLB = PrivateLink
yog927 👍 1 Selected: A
A, VPC endpoint used with NLB
pangchn 👍 4 Selected: A
A This is a privatelink scenrio. Can't find a hard evidence but the Privatelink seem can only work with NLB. If need ALB, it will be Privatelink -> NLB -> ALB one evidence is the link lasithasilva709 posted another evidence is compare of ALB/NLB https://aws.amazon.com/elasticloadbalancing/features/?nc=sn&loc=2&dn=1 3rd evidence https://aws.amazon.com/about-aws/whats-new/2021/09/application-load-balancer-aws-privatelink-static-ip-addresses-network-load-balancer/
lasithasilva709 👍 2 Selected: A
My understanding is that NLB should be used for a VPC endpoint service. Here are some resources: 1. To use AWS PrivateLink, create a Network Load Balancer for your application in your VPC, and create a VPC endpoint service configuration pointing to that load balancer. https://docs.aws.amazon.com/whitepapers/latest/building-scalable-secure-multi-vpc-network-infrastructure/aws-privatelink.html 2. https://aws.amazon.com/blogs/networking-and-content-delivery/application-load-balancer-type-target-group-for-network-load-balancer/
AWSPro1234 👍 2
Answer is A. Many services is a key word , option B is for http and https.
Dgix 👍 2 Selected: B
B is just a safe as A — TCP is not inherently safer. However, HTTPS and HTTP are much more commonly used when providing services to other companies. As we don't have any information as to the nature of the service, a safer bet (pun intended) is B.
CMMC 👍 2 Selected: A
#C & #D are out given the connectivity cannot traverse the internet. #A enables secure VPC endpoint to privately expose to other companies' VPCs without traversing the internet, and TCP to provide more controlled and secure comm protocol for sensitive data

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A VPC endpoint service backed by a Network Load Balancer publishes the on-premises service to AWS customers through PrivateLink. Because the VPC is already reachable over Direct Connect and the VPN, consumer traffic stays on the private network path, which satisfies the requirement that connectivity must not traverse the internet. An NLB is the only load balancer type that can front a VPC endpoint service.

Why the Other Options Are Wrong

B: An Application Load Balancer is layer 7 only and cannot be used with a VPC endpoint service, so HTTP or HTTPS endpoint services on an ALB are not supported. C and D: An internet gateway or a NAT gateway exposes or originates traffic over the public internet, which directly violates the requirement that the data is sensitive and must not traverse the internet.

Community Comment Notes

The community voted 89 to 1 for A, and the main justification was that PrivateLink endpoint services support only a Network Load Balancer or a Gateway Load Balancer, not an Application Load Balancer, and that a NAT or internet gateway path would cross the internet.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide