ETExamTower
Q15Design Cost-Optimized Architectures

A company is building an application that runs in containers within a VPC. The application stores and retrieves data from an Amazon S3 bucket. During the development phase, the application will store and access 1 TB of data in Amazon S3 each day. The company wants to reduce costs and avoid traffic traversing the internet whenever possible. Which solution will meet these requirements?

← → navigate · a answer
Community votes
C
100% (7)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 11
14
Amazon S3 supports both gateway endpoints and interface endpoints. With a gateway endpoint, you can access Amazon S3 from your VPC, without requiring an internet gateway or NAT device for your VPC, and with no additional cost. However, gateway endpoints do not allow access from on-premises networks, from peered VPCs in other AWS Regions, or through a transit gateway. For those scenarios, you must use an interface endpoint, which is available for an additional cost.
C 8
Gateway VPC Endpoint: A gateway VPC endpoint enables private connectivity between a VPC and Amazon S3. It allows direct access to Amazon S3 without the need for internet gateways, NAT devices, VPN connections, or AWS Direct Connect. Minimize Internet Traffic: By creating a gateway VPC endpoint for Amazon S3 and associating it with all route tables in the VPC, the traffic between the VPC and Amazon S3 will be kept within the AWS network. This helps in minimizing data transfer costs and prevents the need for traffic to traverse the internet. Cost-Effective: With a gateway VPC endpoint, the data transfer between the application running in the VPC and the S3 bucket stays within the AWS network, reducing the need for data transfer across the internet. This can result in cost savings, especially when dealing with large amounts of data.
C 5
vpc endpoint for s3
C 4
https://aws.amazon.com/blogs/architecture/choosing-your-vpc-endpoint-strategy-for-amazon-s3/ A: Storage cost is not described as an issue here B: Tx Accelerator is for external (global user) traffic acceleration D: Interface endpoint is on-prem to S3 C: gateway VPC is specifically for S3 to AWS resources
C 4
Prevent traffic from traversing the internet = Gateway VPC endpoint for S3.
C 3
Gateway endpoint for S3
3
Option B (Enable S3 Transfer Acceleration for the S3 bucket) is a feature that uses the CloudFront global network to accelerate data transfers to and from Amazon S3. While it can improve data transfer speed, it still involves traffic traversing the internet and doesn't directly address the goal of minimizing costs and preventing internet traffic whenever possible.
3
I think both C&D will works. But D will have extra cost. So C is correct.
C 2
C. Create a gateway VPC endpoint for Amazon S3. Associate this endpoint with all route tables in the VPC
2
Key word transversing to internet
1
Interface endpoints are not exclusively for on-prem to S3. The only reason why option D is wrong is because "Associate this endpoint with all route tables in the VPC" makes no sense.