AWS Certified Solutions Architect Associate SAA-C03 Practice Question
An organization needs to ensure that its compute instances, which handle sensitive data in an isolated environment, have the ability to securely access object storage without the data traveling over the internet. Which configuration aligns with these stringent security requirements?
Allocate public IP addresses to the compute instances for internet access to the object storage.
Provision a service-specific gateway within the isolated environment for direct object storage access.
Set up a VPN connection from the compute instances to the object storage service.
Install a NAT device in the isolated environment to route traffic to the object storage.