AWS Certified Data Engineer Associate DEA-C01 Practice Question
A data engineering team must expose a JSON ingestion REST endpoint to several financial partners. Company policy requires each partner to authenticate by presenting an X.509 client certificate issued by the partner's intermediate CA. The endpoint must be reachable only from the company VPC, and the team wants to avoid writing custom certificate-validation logic. Which solution meets these requirements with the least operational overhead?
Create a private Amazon API Gateway REST API, enable mutual TLS with a trust store that contains the partners' CA certificates, and access the API through an interface VPC endpoint.
Issue an IAM access key and secret key to each partner and require Signature Version 4-signed HTTPS requests to an Internet-facing API Gateway endpoint secured with IAM authorization.
Deploy an internal Application Load Balancer with an HTTPS listener configured for mutual TLS verify mode. Create an ELB trust store containing the partners' CA certificates in Amazon S3 and attach it to the listener.
Provide partners with presigned Amazon S3 PUT URLs secured with TLS 1.2 so they can upload their data files.
An internal Application Load Balancer (ALB) can terminate TLS and perform mutual TLS verification. The team uploads a CA bundle that trusts the partners' intermediate CAs to an ELB trust store stored in Amazon S3, attaches the trust store to an HTTPS listener in mutual TLS verify mode, and targets the ALB at the ingestion service. The ALB authenticates client certificates during the TLS handshake and blocks untrusted connections, so no backend changes are needed. Because the ALB is internal and secured by VPC security groups, the endpoint is accessible only from the company VPC. The other options either rely on presigned URLs, IAM Signature Version 4, or OAuth tokens-which are key- or token-based, not certificate-based-or attempt to use mutual TLS with a private API Gateway REST API, which is not supported.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is mutual TLS and how does it work?
Open an interactive chat with Bash
What is an ELB trust store, and how is it used in mutual TLS?
Open an interactive chat with Bash
Why is an internal Application Load Balancer preferred over API Gateway in this scenario?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .