SAP-C02 exam dumps

SAP-C02 practice question 118 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 118

Select 2

A company has multiple AWS accounts for different environments: development, testing, and production. They need to share a centralized Amazon RDS database hosted in the production account with applications running in the development and testing accounts. The database should only be accessible to specific applications in these accounts. Which approach should the company use to meet this requirement securely and efficiently?

  1. A

    Use AWS Resource Access Manager (RAM) to share the RDS database subnet group with the development and testing accounts.

  2. B

    Enable VPC peering between the production VPC and the VPCs in the development and testing accounts, and configure appropriate security groups and route tables.

  3. C

    Create database users with limited permissions for the development and testing accounts and provide application credentials to access the RDS database.

  4. D

    Use AWS Resource Access Manager (RAM) to share the RDS database directly with the development and testing accounts.

  5. E

    Set up an AWS Transit Gateway to interconnect the VPCs and control access using security groups and network ACLs.

Show answer and explanation

Correct answers: B, E

Explanation

To securely share an RDS database across multiple accounts, it is crucial to establish private network connectivity between the VPCs hosting the applications and the database. Both VPC peering and AWS Transit Gateway provide secure and scalable solutions for this use case. VPC peering is simpler and suitable for smaller setups, while AWS Transit Gateway is more scalable for environments with multiple VPCs. In both cases, security groups and route tables should be configured to restrict access to the RDS database from only the required applications in the development and testing accounts.

  • A. Incorrect.

    Incorrect: AWS RAM cannot be used to share RDS database subnet groups. RAM is used to share specific resources like subnets, Route 53 resolver rules, and Transit Gateways, but not RDS databases or their subnet groups.

  • B. Correct.

    Correct: VPC peering allows private connectivity between VPCs, enabling the development and testing accounts to access the RDS database hosted in the production VPC. Security groups and route tables can be configured to restrict access to only the necessary applications.

  • C. Incorrect.

    Incorrect: While creating database users with limited permissions provides some level of control, sharing credentials across accounts is not a secure or scalable solution. This approach does not address network-level access controls either.

  • D. Incorrect.

    Incorrect: AWS RAM does not support directly sharing RDS databases. RDS instances cannot be shared across accounts directly using RAM.

  • E. Correct.

    Correct: AWS Transit Gateway provides a scalable solution to interconnect multiple VPCs, allowing the development and testing accounts to securely access the RDS database in the production account. Security groups and network ACLs can be configured to enforce access control.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam