AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company is migrating several petabytes of data from an on-premises NFS server to Amazon FSx for NetApp ONTAP. The company has a 10 Gbps AWS Direct Connect connection established between its data center and a dedicated VPC. A strict corporate security policy mandates that all data transfer traffic related to this migration must remain within a private network and must not traverse the public internet. The solutions architect has selected AWS DataSync for the migration.
Which configuration should the architect implement to meet the security requirement?
Deploy the DataSync agent on a server in the on-premises data center. Create an interface VPC endpoint for DataSync in the VPC and configure the agent to use this endpoint.
Deploy the DataSync agent on an Amazon EC2 instance in the VPC. Mount the on-premises NFS share to this EC2 instance over the Direct Connect connection.
Deploy the DataSync agent on a server in the on-premises data center. Configure the agent to use the public service endpoint and restrict the agent's security group to allow egress traffic only to the DataSync public IP address ranges.
Configure an AWS Transfer Family server with an endpoint in the VPC. Use a custom script to mount the on-premises NFS share and transfer the data via the Transfer Family server over the Direct Connect connection.
The correct answer is to deploy the AWS DataSync agent on-premises and use an interface VPC endpoint for DataSync in the VPC. AWS DataSync supports AWS PrivateLink, which allows you to create a private endpoint for the DataSync service within your VPC. When the on-premises agent is configured to use this interface VPC endpoint, all communication, including agent activation and data transfer, is routed securely over the AWS Direct Connect connection to the endpoint's elastic network interface (ENI) in the VPC. This ensures that no migration traffic ever traverses the public internet, satisfying the strict security requirement.
Deploying the DataSync agent on an EC2 instance in the VPC and mounting the on-premises NFS share is an anti-pattern. The agent is designed to be deployed close to the source data to optimize performance and reduce complexity. Pulling the data across the Direct Connect connection before it even reaches the agent is inefficient.
Using a public service endpoint, even with restrictive security group rules, would still route traffic over the public internet, which explicitly violates the core security requirement of the company. Security groups act as a firewall but do not change the network path of the traffic.
Using AWS Transfer Family is not the optimal solution for a large-scale file system migration. While Transfer Family is excellent for file-based workflows over SFTP, FTPS, and FTP, AWS DataSync is purpose-built for accelerating large-scale online data transfers between on-premises storage and AWS services like Amazon FSx.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS DataSync, and why is it used for migrations?
Open an interactive chat with Bash
What is an interface VPC endpoint and how does it differ from a public endpoint?
Open an interactive chat with Bash
Why is deploying the DataSync agent on-premises preferred over using Amazon EC2 in this scenario?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access