exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 719 discussion

A company has a data lake in Amazon S3 that needs to be accessed by hundreds of applications across many AWS accounts. The company's information security policy states that the S3 bucket must not be accessed over the public internet and that each application should have the minimum permissions necessary to function.
To meet these requirements, a solutions architect plans to use an S3 access point that is restricted to specific VPCs for each application.
Which combination of steps should the solutions architect take to implement this solution? (Choose two.)

  • A. Create an S3 access point for each application in the AWS account that owns the S3 bucket. Configure each access point to be accessible only from the application's VPC. Update the bucket policy to require access from an access point
  • B. Create an interface endpoint for Amazon S3 in each application's VPC. Configure the endpoint policy to allow access to an S3 access point. Create a VPC gateway attachment for the S3 endpoint
  • C. Create a gateway endpoint for Amazon S3 in each application's VPC. Configure the endpoint policy to allow access to an S3 access point. Specify the route table that is used to access the access point.
  • D. Create an S3 access point for each application in each AWS account and attach the access points to the S3 bucket. Configure each access point to be accessible only from the application's VPC. Update the bucket policy to require access from an access point.
  • E. Create a gateway endpoint for Amazon S3 in the data lake's VPC. Attach an endpoint policy to allow access to the S3 bucket. Specify the route table that is used to access the bucket
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
beebatov
Highly Voted 3 years, 2 months ago
A & C. https://joe.blog.freemansoft.com/2020/04/protect-data-in-cloud-with-s3-access.html
upvoted 6 times
...
Simon523
Most Recent 1 year, 3 months ago
Selected Answer: AC
https://docs.aws.amazon.com/vpc/latest/privatelink/gateway-endpoints.html
upvoted 1 times
...
SkyZeroZx
1 year, 5 months ago
Selected Answer: AC
A & C look to be the "best" options.
upvoted 1 times
...
janvandermerwer
2 years ago
Selected Answer: AC
A & C look to be the "best" options.
upvoted 1 times
...
Sumit_Kumar
2 years, 3 months ago
https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-access-points/
upvoted 1 times
...
xyzman
2 years, 5 months ago
It's A,C but the path is App --> S3 Gateway Endpoint --> S3 Access Point --> S3 Bucket
upvoted 1 times
...
pal40sg
2 years, 9 months ago
Selected Answer: AC
It's A,C App --> S3 Access Point --> S3 Gateway Endpoint --> S3 Bucket
upvoted 1 times
JohnPi
2 years, 2 months ago
path is App --> S3 Gateway Endpoint --> S3 Access Point --> S3 Bucket
upvoted 1 times
...
...
AzureDP900
2 years, 12 months ago
A,C is right
upvoted 1 times
...
andylogan
3 years, 1 month ago
It's A,C App --> S3 Access Point --> S3 Gateway Endpoint --> S3 Bucket
upvoted 3 times
JohnPi
2 years, 2 months ago
path is App --> S3 Gateway Endpoint --> S3 Access Point --> S3 Bucket
upvoted 2 times
...
...
Goram113
3 years, 1 month ago
can't see this route step here https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-access-points/ but A&C seems to be the best '
upvoted 1 times
...
student22
3 years, 1 month ago
A,C App --> S3 Access Point --> S3 Gateway Endpoint --> S3 Bucket
upvoted 3 times
...
tgv
3 years, 1 month ago
AAA CCC ---
upvoted 1 times
...
WhyIronMan
3 years, 1 month ago
I'll go with A, C
upvoted 2 times
...
Waiweng
3 years, 1 month ago
it's A&C
upvoted 2 times
...
mustpassla
3 years, 1 month ago
A & C, https://aws.amazon.com/s3/features/access-points/
upvoted 1 times
...
vkbajoria
3 years, 1 month ago
It is A & C.
upvoted 1 times
...
tvs
3 years, 2 months ago
AC https://aws.amazon.com/s3/features/access-points/ & https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-access-points/
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...