AWS Certified Data Engineer Associate DEA-C01 Practice Question
An AWS Glue job runs in a private subnet and must load data into an Amazon Redshift cluster that resides in a different VPC connected through a VPC peering link. The job times out when it tries to connect to the cluster on port 5439. Which change will enable the connection while following the principle of least privilege?
Add a route in the Glue subnet's route table that sends all 0.0.0.0/0 traffic through the VPC peering connection.
Create a custom network ACL for the Redshift subnet that allows inbound TCP 5439 from the Glue subnet's CIDR range.
Attach an IAM policy to the Glue job's execution role that grants the redshift:DescribeClusters permission.
Add an inbound rule to the Redshift cluster's security group that allows TCP 5439 traffic from the security group used by the Glue job.
Traffic to Amazon Redshift is allowed only when the cluster's security group permits inbound TCP 5439 from the client. By adding an inbound rule that references the security group attached to the Glue job's ENIs, the rule is limited to exactly those resources that need access. Route-table entries already exist for peered CIDR blocks, and security groups are stateful, so no outbound rule is required. Network ACLs are optional and IAM policies cannot open network ports, so those alternatives will not resolve the timeout.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does adding an inbound rule to the Redshift cluster's security group enable the Glue job to connect?
Open an interactive chat with Bash
Why are route table entries not necessary for VPC peering connections in this setup?
Open an interactive chat with Bash
Why can't IAM policies solve network connection issues like timeouts?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Security and Governance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .