AWS Certified Data Engineer Associate DEA-C01 Practice Question
An organization is using AWS DMS to migrate data from an on-premises Oracle database to an Amazon Redshift cluster in a public subnet. A security audit mandates that only the DMS replication instance may open a TCP connection to the cluster on port 5439. What is the MOST secure way to implement this requirement?
Attach an AWS WAF web ACL to the Redshift endpoint that allows the replication instance's IP address and blocks all others.
Enable enhanced VPC routing on the Redshift cluster so that only resources in the same VPC can initiate connections.
Add an inbound rule to the Redshift cluster's security group that allows port 5439 traffic only from the DMS replication instance's private IP address.
Configure a network ACL on the Redshift subnets that denies all inbound traffic except port 5439 from the replication instance's IP address.
Amazon Redshift controls network access through the VPC security groups that are associated with the cluster. Adding an inbound rule that allows traffic on port 5439 only from the replication instance's IP address (or its security group) creates an IP allowlist that blocks every other source. AWS WAF cannot attach to a Redshift endpoint, network ACLs are stateless and harder to manage than security groups, and enhanced VPC routing governs data‐path routing rather than connection filtering.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Redshift security group?
Open an interactive chat with Bash
Why can’t AWS WAF attach to a Redshift endpoint?
Open an interactive chat with Bash
What is enhanced VPC routing and why isn’t it applicable here?
Open an interactive chat with Bash
AWS Certified Data Engineer Associate DEA-C01
Data Ingestion and Transformation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .