Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 421 discussion

A company runs a highly available SFTP service. The SFTP service uses two Amazon EC2 Linux instances that run with elastic IP addresses to accept traffic from trusted IP sources on the internet. The SFTP service is backed by shared storage that is attached to the instances. User accounts are created and managed as Linux users in the SFTP servers.

The company wants a serverless option that provides high IOPS performance and highly configurable security. The company also wants to maintain control over user permissions.

Which solution will meet these requirements?

  • A. Create an encrypted Amazon Elastic Block Store (Amazon EBS) volume. Create an AWS Transfer Family SFTP service with a public endpoint that allows only trusted IP addresses. Attach the EBS volume to the SFTP service endpoint. Grant users access to the SFTP service.
  • B. Create an encrypted Amazon Elastic File System (Amazon EFS) volume. Create an AWS Transfer Family SFTP service with elastic IP addresses and a VPC endpoint that has internet-facing access. Attach a security group to the endpoint that allows only trusted IP addresses. Attach the EFS volume to the SFTP service endpoint. Grant users access to the SFTP service.
  • C. Create an Amazon S3 bucket with default encryption enabled. Create an AWS Transfer Family SFTP service with a public endpoint that allows only trusted IP addresses. Attach the S3 bucket to the SFTP service endpoint. Grant users access to the SFTP service.
  • D. Create an Amazon S3 bucket with default encryption enabled. Create an AWS Transfer Family SFTP service with a VPC endpoint that has internal access in a private subnet. Attach a security group that allows only trusted IP addresses. Attach the S3 bucket to the SFTP service endpoint. Grant users access to the SFTP service.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
alexandercamachop
Highly Voted 1 year, 5 months ago
Selected Answer: B
First Serverless - EFS Second it says it is attached to the Linux instances at the same time, only EFS can do that.
upvoted 6 times
...
pentium75
Highly Voted 10 months, 3 weeks ago
Selected Answer: B
Not A - Transfer Family canj't use EBS B - Possible and meets requirement Not C - S3 doesn't guarantee "high IOPS performance"; also there is no "public endpoint that allows only trusted IP addresses" (you can assign a Security Group to a public endpoint but that is not mentioned here) Not D - Endpoint would be in private subnet, not accessible from Internet at all
upvoted 6 times
...
523db89
Most Recent 3 months ago
Option B best meets the company's requirements by leveraging AWS Transfer Family with an EFS volume, ensuring high availability, security, and performance.
upvoted 1 times
...
NickGordon
1 year ago
Selected Answer: B
A is incorrect as EBS is not an option C is incorrect as when I select public accessible, I don't see an option I can set up trusted IP address D isi incorrect as it is internal. B, followed the steps and I can set up a sftp in this way
upvoted 3 times
...
potomac
1 year ago
Selected Answer: B
B EFS has lower latency and higher throughput than S3 when accessed from within the same availability zone.
upvoted 2 times
...
thanhnv142
1 year, 1 month ago
C: Because it is server-less. deffinitely not A or B because it utilizes server.
upvoted 1 times
warp
1 year, 1 month ago
Amazon Elastic File System - Serverless, fully elastic file storage: https://aws.amazon.com/efs/
upvoted 4 times
...
...
bsbs1234
1 year, 1 month ago
B, A), transfer family does not support EBS C,D), S3 has lower IOPS than EFS
upvoted 3 times
...
Guru4Cloud
1 year, 2 months ago
Selected Answer: B
Create an encrypted Amazon Elastic File System (Amazon EFS) volume. Create an AWS Transfer Family SFTP service with elastic IP addresses and a VPC endpoint that has internet-facing access. Attach a security group to the endpoint that allows only trusted IP addresses. Attach the EFS volume to the SFTP service endpoint. Grant users access to the SFTP service.
upvoted 1 times
...
Axeashes
1 year, 5 months ago
https://aws.amazon.com/blogs/storage/use-ip-whitelisting-to-secure-your-aws-transfer-for-sftp-servers/
upvoted 1 times
...
TariqKipkemei
1 year, 5 months ago
Selected Answer: B
EFS is best to serve this purpose.
upvoted 1 times
...
envest
1 year, 5 months ago
Answer C (from abylead.com) Transfer Family offers fully managed serverless support for B2B file transfers via SFTP, AS2, FTPS, & FTP directly in & out of S3 or EFS. For a controlled internet access you can use internet-facing endpts with Transfer SFTP servers & restrict trusted internet sources with VPC's default Sgrp. In addition, S3 Access Points aliases allows you to use S3 bkt names for a unique access control plcy on shared S3 datasets. Transfer SFTP & S3: https://aws.amazon.com/blogs/apn/how-to-use-aws-transfer-family-to-replace-and-scale-sftp-servers/ A)Transfer SFTP doesn’t support EBS, not for share data, & not serverless: infeasible. B)EFS mounts via ENIs not endpts: infeasible. D)pub endpt for internet access is missing: infeasible.
upvoted 4 times
...
omoakin
1 year, 5 months ago
BBBBBBBBBBBBBB
upvoted 1 times
...
vesen22
1 year, 5 months ago
Selected Answer: B
EFS all day
upvoted 2 times
...
norris81
1 year, 5 months ago
https://aws.amazon.com/blogs/storage/use-ip-whitelisting-to-secure-your-aws-transfer-for-sftp-servers/ is worth a read
upvoted 2 times
...
odjr
1 year, 5 months ago
Selected Answer: B
EFS is serverless. There is no reference in S3 about IOPS
upvoted 2 times
...
willyfoogg
1 year, 5 months ago
Selected Answer: B
Option D is incorrect because it suggests using an S3 bucket in a private subnet with a VPC endpoint, which may not meet the requirement of maintaining control over user permissions as effectively as the EFS-based solution.
upvoted 2 times
...
anibinaadi
1 year, 5 months ago
It is D Refer https://docs.aws.amazon.com/transfer/latest/userguide/create-server-in-vpc.html for further details.
upvoted 1 times
pentium75
10 months, 3 weeks ago
In D you create an "endpoint that has internal access in a private subnet", how to access that from the Internet?
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...