Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 421 discussion

A company runs a highly available SFTP service. The SFTP service uses two Amazon EC2 Linux instances that run with elastic IP addresses to accept traffic from trusted IP sources on the internet. The SFTP service is backed by shared storage that is attached to the instances. User accounts are created and managed as Linux users in the SFTP servers.

The company wants a serverless option that provides high IOPS performance and highly configurable security. The company also wants to maintain control over user permissions.

Which solution will meet these requirements?

  • A. Create an encrypted Amazon Elastic Block Store (Amazon EBS) volume. Create an AWS Transfer Family SFTP service with a public endpoint that allows only trusted IP addresses. Attach the EBS volume to the SFTP service endpoint. Grant users access to the SFTP service.
  • B. Create an encrypted Amazon Elastic File System (Amazon EFS) volume. Create an AWS Transfer Family SFTP service with elastic IP addresses and a VPC endpoint that has internet-facing access. Attach a security group to the endpoint that allows only trusted IP addresses. Attach the EFS volume to the SFTP service endpoint. Grant users access to the SFTP service.
  • C. Create an Amazon S3 bucket with default encryption enabled. Create an AWS Transfer Family SFTP service with a public endpoint that allows only trusted IP addresses. Attach the S3 bucket to the SFTP service endpoint. Grant users access to the SFTP service.
  • D. Create an Amazon S3 bucket with default encryption enabled. Create an AWS Transfer Family SFTP service with a VPC endpoint that has internal access in a private subnet. Attach a security group that allows only trusted IP addresses. Attach the S3 bucket to the SFTP service endpoint. Grant users access to the SFTP service.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
pentium75
Highly Voted 6 months, 1 week ago
Selected Answer: B
Not A - Transfer Family canj't use EBS B - Possible and meets requirement Not C - S3 doesn't guarantee "high IOPS performance"; also there is no "public endpoint that allows only trusted IP addresses" (you can assign a Security Group to a public endpoint but that is not mentioned here) Not D - Endpoint would be in private subnet, not accessible from Internet at all
upvoted 5 times
...
NickGordon
Most Recent 8 months ago
Selected Answer: B
A is incorrect as EBS is not an option C is incorrect as when I select public accessible, I don't see an option I can set up trusted IP address D isi incorrect as it is internal. B, followed the steps and I can set up a sftp in this way
upvoted 3 times
...
potomac
8 months ago
Selected Answer: B
B EFS has lower latency and higher throughput than S3 when accessed from within the same availability zone.
upvoted 2 times
...
thanhnv142
8 months, 2 weeks ago
C: Because it is server-less. deffinitely not A or B because it utilizes server.
upvoted 1 times
warp
8 months, 2 weeks ago
Amazon Elastic File System - Serverless, fully elastic file storage: https://aws.amazon.com/efs/
upvoted 3 times
...
...
bsbs1234
9 months, 1 week ago
B, A), transfer family does not support EBS C,D), S3 has lower IOPS than EFS
upvoted 3 times
...
Guru4Cloud
10 months, 1 week ago
Selected Answer: B
Create an encrypted Amazon Elastic File System (Amazon EFS) volume. Create an AWS Transfer Family SFTP service with elastic IP addresses and a VPC endpoint that has internet-facing access. Attach a security group to the endpoint that allows only trusted IP addresses. Attach the EFS volume to the SFTP service endpoint. Grant users access to the SFTP service.
upvoted 1 times
...
Axeashes
1 year ago
https://aws.amazon.com/blogs/storage/use-ip-whitelisting-to-secure-your-aws-transfer-for-sftp-servers/
upvoted 1 times
...
TariqKipkemei
1 year, 1 month ago
Selected Answer: B
EFS is best to serve this purpose.
upvoted 1 times
...
alexandercamachop
1 year, 1 month ago
Selected Answer: B
First Serverless - EFS Second it says it is attached to the Linux instances at the same time, only EFS can do that.
upvoted 4 times
...
envest
1 year, 1 month ago
Answer C (from abylead.com) Transfer Family offers fully managed serverless support for B2B file transfers via SFTP, AS2, FTPS, & FTP directly in & out of S3 or EFS. For a controlled internet access you can use internet-facing endpts with Transfer SFTP servers & restrict trusted internet sources with VPC's default Sgrp. In addition, S3 Access Points aliases allows you to use S3 bkt names for a unique access control plcy on shared S3 datasets. Transfer SFTP & S3: https://aws.amazon.com/blogs/apn/how-to-use-aws-transfer-family-to-replace-and-scale-sftp-servers/ A)Transfer SFTP doesn’t support EBS, not for share data, & not serverless: infeasible. B)EFS mounts via ENIs not endpts: infeasible. D)pub endpt for internet access is missing: infeasible.
upvoted 4 times
...
omoakin
1 year, 1 month ago
BBBBBBBBBBBBBB
upvoted 1 times
...
vesen22
1 year, 1 month ago
Selected Answer: B
EFS all day
upvoted 2 times
...
norris81
1 year, 1 month ago
https://aws.amazon.com/blogs/storage/use-ip-whitelisting-to-secure-your-aws-transfer-for-sftp-servers/ is worth a read
upvoted 2 times
...
odjr
1 year, 1 month ago
Selected Answer: B
EFS is serverless. There is no reference in S3 about IOPS
upvoted 2 times
...
willyfoogg
1 year, 1 month ago
Selected Answer: B
Option D is incorrect because it suggests using an S3 bucket in a private subnet with a VPC endpoint, which may not meet the requirement of maintaining control over user permissions as effectively as the EFS-based solution.
upvoted 2 times
...
anibinaadi
1 year, 1 month ago
It is D Refer https://docs.aws.amazon.com/transfer/latest/userguide/create-server-in-vpc.html for further details.
upvoted 1 times
pentium75
6 months, 1 week ago
In D you create an "endpoint that has internal access in a private subnet", how to access that from the Internet?
upvoted 1 times
...
...
elmogy
1 year, 1 month ago
Selected Answer: B
EFS is serverless and has high IOPS. regardless the IOPS, I believe option D is incorrect because it is internal, and the request needs internet access
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in