Instances in a private subnet write several terabytes a month to Amazon S3. That traffic currently leaves through a NAT gateway. Security wants it to stay on the AWS network, and finance has noticed the NAT gateway's data processing charges. What addresses both?

AWS Certified Cloud Practitioner (CLF-C02), objective 3. Cloud technology and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct Create a gateway VPC endpoint for S3 and route S3-bound traffic to it

Correct. The endpoint keeps the traffic inside the AWS network instead of sending it out through the NAT gateway, which satisfies security, and gateway endpoints for S3 carry no hourly or per-gigabyte charge, which satisfies finance.

Not correct Move the instances into a public subnet

Wrong on both counts. It exposes the instances directly to the internet and the traffic to S3 still goes out over the internet path, so nothing about the security requirement is met.

Not correct Set up AWS Direct Connect

Wrong. Direct Connect links a data centre outside AWS to a VPC. Both ends here are already inside AWS, in the same Region.

Not correct Make the bucket public so the instances can reach it without a NAT gateway

Wrong, and dangerous. A bucket policy decides WHO may read the objects, not which network path the request takes — so this would not remove the NAT gateway from the path while exposing customer data to the world.

Why

VPC endpoints give private access to AWS services without an internet gateway, a NAT gateway or a public IP address. There are two kinds and the difference shows up on the bill: gateway endpoints, which exist for S3 and DynamoDB, are entries in a route table and cost nothing; interface endpoints, powered by AWS PrivateLink, place an elastic network interface with a private IP address in your subnet for most other services and are charged per hour and per gigabyte.

Where this comes from

Cited
AWS exam guide task statement 3.5

Practise this

Reading one question is not practice. The trainer will draw a set from objective 3 and space the ones you get wrong.

Practise AWS Certified Cloud Practitioner (CLF-C02)

More questions on this objective

All questions on Cloud technology and services