AWS Certified Data Engineer Associate DEA-C01 Practice Question

A data engineering team runs an Amazon EMR cluster in a private subnet. The cluster must download libraries from an Amazon S3 bucket, and company policy prohibits any traffic that leaves the VPC. All requests must be signed by the cluster's IAM instance profile; no other principals in the VPC should reach the bucket. Which network configuration meets these requirements in the most operationally efficient way?

  • Deploy a NAT gateway in a public subnet and route the EMR subnet's traffic to Amazon S3 through the NAT gateway.

  • Establish VPC peering to a separate VPC that hosts an S3 proxy, and route the EMR subnet's traffic through the peered connection.

  • Create a gateway VPC endpoint for Amazon S3 and attach an endpoint policy that allows access only from the EMR cluster's IAM role.

  • Create an interface VPC endpoint for Amazon S3 and associate it with the EMR subnet's security group.

AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot