exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 223 discussion

A company has deployed a Java Spring Boot application as a pod that runs on Amazon Elastic Kubernetes Service (Amazon EKS) in private subnets. The application needs to write data to an Amazon DynamoDB table. A solutions architect must ensure that the application can interact with the DynamoDB table without exposing traffic to the internet.

Which combination of steps should the solutions architect take to accomplish this goal? (Choose two.)

  • A. Attach an IAM role that has sufficient privileges to the EKS pod.
  • B. Attach an IAM user that has sufficient privileges to the EKS pod.
  • C. Allow outbound connectivity to the DynamoDB table through the private subnets’ network ACLs.
  • D. Create a VPC endpoint for DynamoDB.
  • E. Embed the access keys in the Java Spring Boot code.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Burrito69
3 months ago
After seeing D, I didn't even look at option E. its AD correct
upvoted 2 times
...
awsgeek75
5 months, 1 week ago
Selected Answer: AD
B: Wrong, cannot be a user for EKS C: Not possible as NACL need destination CIDR/ports etc. This is not correct way to connect to DynamoDB E: Not secure AD is correct because you need roles for allowing service permissions and accessing DynamoDB with VPC endpoint is the correct way
upvoted 3 times
...
Ruffyit
7 months, 1 week ago
The application needs to write data to an Amazon DynamoDB table = Attach an IAM role that has write privileges to the EKS pod Without exposing traffic to the internet = VPC endpoint for DynamoDB
upvoted 2 times
...
TariqKipkemei
9 months ago
Selected Answer: AD
The application needs to write data to an Amazon DynamoDB table = Attach an IAM role that has write privileges to the EKS pod Without exposing traffic to the internet = VPC endpoint for DynamoDB
upvoted 4 times
...
Guru4Cloud
9 months, 2 weeks ago
Selected Answer: AD
A. By attaching an IAM role to the EKS pod, you can grant the necessary permissions for the pod to access DynamoDB. The IAM role should have appropriate policies allowing access to the DynamoDB table. D. Creating a VPC endpoint for DynamoDB allows the EKS pod to access DynamoDB privately within the VPC, without the need for internet connectivity. The VPC endpoint provides a direct and secure connection to DynamoDB, eliminating the need for traffic to flow over the internet.
upvoted 3 times
...
cookieMr
12 months ago
Selected Answer: AD
A. By attaching an IAM role to the EKS pod, you can grant the necessary permissions for the pod to access DynamoDB. The IAM role should have appropriate policies allowing access to the DynamoDB table. D. Creating a VPC endpoint for DynamoDB allows the EKS pod to access DynamoDB privately within the VPC, without the need for internet connectivity. The VPC endpoint provides a direct and secure connection to DynamoDB, eliminating the need for traffic to flow over the internet. B is incorrect because attaching an IAM user to the pod is not a recommended approach. IAM users are meant for accessing AWS services through the AWS Management Console or AP. C is incorrect because configuring outbound connectivity through network ACLs would not provide a secure and direct connection to DynamoDB. E is incorrect because embedding access keys in the code is not a recommended security practice. It can lead to potential security vulnerabilities. It is better to use IAM roles or other secure mechanisms for providing access to AWS services.
upvoted 3 times
...
Bmarodi
1 year ago
Selected Answer: AD
A & D options fulfill the requirements.
upvoted 2 times
...
LuckyAro
1 year, 5 months ago
Selected Answer: AD
Definitely
upvoted 2 times
...
Aninina
1 year, 5 months ago
Selected Answer: AD
A D are the correct options
upvoted 2 times
...
venice1234
1 year, 5 months ago
Selected Answer: AD
https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/vpc-endpoints-dynamodb.html https://aws.amazon.com/about-aws/whats-new/2019/09/amazon-eks-adds-support-to-assign-iam-permissions-to-kubernetes-service-accounts/
upvoted 3 times
...
Parsons
1 year, 5 months ago
Selected Answer: AD
A, D is the correct answer.
upvoted 3 times
...
mhmt4438
1 year, 5 months ago
Selected Answer: AD
The correct answer is A,D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago