AWS Certified Data Engineer Associate DEA-C01 Practice Question
A data engineer is building an Amazon MWAA environment in two private subnets that lack internet or a NAT gateway. DAGs, plugins, and requirements.txt are stored in an Amazon S3 bucket in the same Region. Creation fails, and CloudWatch Logs show time-outs when connecting to s3.amazonaws.com. The company must fix the problem without exposing the subnets to the internet. What should they do?
Add s3:GetObject and s3:ListBucket permissions to the MWAA execution role.
Enable cross-origin resource sharing (CORS) on the S3 bucket that stores the DAGs.
Create a gateway VPC endpoint for Amazon S3 and add it to the route tables of the private subnets.
Attach an internet gateway to the VPC and add a 0.0.0.0/0 route to the private subnets.
When an Amazon MWAA environment starts, its scheduler downloads DAGs and other assets from Amazon S3. Private subnets without a NAT gateway cannot reach the public S3 endpoints, so the connection times out and creation fails. Adding a gateway VPC endpoint for Amazon S3 and associating it with the subnets' route tables provides private connectivity to S3 without making the subnets public. Changing IAM permissions or CORS configuration does not address the blocked network path, and attaching an internet gateway would violate the requirement to keep the subnets private.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a gateway VPC endpoint in AWS?
Open an interactive chat with Bash
Why doesn't adding s3:GetObject and s3:ListBucket permissions to the MWAA execution role fix the issue?
Open an interactive chat with Bash
How does a VPC endpoint maintain subnet privacy when accessing S3?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Operations and Support
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .