DEA-C01 exam dumps

DEA-C01 practice question 429 of 550

AWS Certified Data Engineer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DEA-C01 Question 429

Select 3

Your company is running a data processing application on Amazon EMR within a VPC. To improve security, your team needs to ensure that the EMR cluster can only communicate with an Amazon S3 bucket in the same region without using a public IP address. Which of the following actions should you take to meet this requirement?

  1. A

    Create a VPC endpoint for Amazon S3 and update the EMR cluster's security group to allow traffic to the endpoint.

  2. B

    Enable S3 Transfer Acceleration for the S3 bucket.

  3. C

    Create an IAM policy allowing the EMR cluster to access the S3 bucket and attach it to the cluster's IAM role.

  4. D

    Update the route table of the subnet hosting the EMR cluster to include a route to the S3 endpoint.

  5. E

    Modify the S3 bucket policy to deny requests that do not originate from the VPC endpoint.

Show answer and explanation

Correct answers: A, D, E

Explanation

To ensure secure communication between the EMR cluster and the S3 bucket without using a public IP address, you must set up a VPC endpoint for Amazon S3. The route table for the subnet must be updated to route S3 traffic through the endpoint, and a bucket policy should be applied to restrict access to requests originating from the VPC endpoint. These steps ensure both security and compliance with the requirement to avoid public IPs. IAM policies, while needed for permission management, do not control network traffic routing.

  • A. Correct.

    Correct: Creating a VPC endpoint for Amazon S3 allows private communication between the EMR cluster and S3 without requiring a public IP address.

  • B. Incorrect.

    Incorrect: S3 Transfer Acceleration is used for speeding up transfers over the public internet and does not address the requirement of avoiding public IP addresses.

  • C. Incorrect.

    Incorrect: While an IAM policy is necessary for authorization, it does not ensure the traffic remains within the VPC or avoids public IPs.

  • D. Correct.

    Correct: Updating the route table to include a route to the S3 endpoint ensures that traffic destined for S3 is routed via the VPC endpoint.

  • E. Correct.

    Correct: Modifying the S3 bucket policy to deny requests that do not originate from the VPC endpoint enforces the security constraint that only traffic from the VPC endpoint can access the bucket.

Timed practice exam

Take a DEA-C01 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam