SAP-C02 exam dumps

SAP-C02 practice question 117 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 117

Single answer

Your organization operates multiple AWS accounts for isolation and management of different environments (e.g., Development, QA, and Production). You have a shared Amazon RDS database hosted in the Production account that needs to be accessed by applications running in the Development and QA accounts. Which solution enables secure and efficient resource sharing across accounts while maintaining least privilege?

  1. A

    Use AWS Resource Access Manager (RAM) to share the RDS database subnet group with the Development and QA accounts.

  2. B

    Use AWS Resource Access Manager (RAM) to share the RDS database with the Development and QA accounts and configure cross-account IAM roles for access.

  3. C

    Create VPC peering connections between the Production account's VPC and the VPCs in the Development and QA accounts, then use security groups to allow database access.

  4. D

    Set up a centralized account with a shared RDS database and configure all environments to access it using cross-account IAM roles.

Show answer and explanation

Correct answer: B

Explanation

The best practice for securely sharing resources across AWS accounts is to use AWS Resource Access Manager (RAM) for supported resources and IAM roles for fine-grained access control. In this scenario, RAM can share the RDS database while IAM roles enforce least privilege access for the Development and QA accounts. This approach is secure, scalable, and aligns with AWS multi-account best practices.

  • A. Incorrect.

    AWS Resource Access Manager (RAM) cannot be used to share RDS database subnet groups. RAM is used to share supported AWS resources like VPCs, Transit Gateways, and others, but not RDS databases or their subnet groups.

  • B. Correct.

    This is the correct answer. AWS Resource Access Manager (RAM) allows securely sharing the RDS database across accounts, and using cross-account IAM roles ensures least privilege access to the database.

  • C. Incorrect.

    While VPC peering can allow access to an RDS database across accounts, it requires additional manual configurations such as managing routes and security groups. It is less efficient and scalable compared to using RAM and IAM roles.

  • D. Incorrect.

    Centralizing all environments in a single account increases operational complexity and goes against the best practice of account isolation. It does not align with the scenario's goal of accessing a shared database while maintaining isolation between environments.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam