AWS SAA-C03 · Question 11 · Domain 1.2: Secure Workloads
A company has an application running on Amazon EC2 instances in a private subnet. The application needs to securely access Amazon S3 to download configuration files. The security team dictates that traffic between the EC2 instances and S3 must not traverse the public internet. <br/><br/>Which solution meets these requirements MOST cost-effectively?
Answer options:
Deploy a NAT Gateway in a public subnet and route S3 traffic through it.
Create an Interface VPC Endpoint (AWS PrivateLink) for Amazon S3.
Create a Gateway VPC Endpoint for Amazon S3 and update the route table.
Set up an AWS Direct Connect connection between the VPC and Amazon S3.
65 questions · hints · full answers · grading