AWS SAP-C02 · Question 32 · Domain 1.1: Network Connectivity
A company is building a machine learning pipeline. Data scientists need to access sensitive datasets stored in Amazon S3. The security team requires that the data scientists' access to S3 must not traverse the public internet. The data scientists use Amazon SageMaker notebook instances deployed in a private VPC subnet. How should the architect secure the S3 access?
Answer options:
Deploy a NAT Gateway in a public subnet and route S3 traffic through it.
Create a Gateway VPC Endpoint for Amazon S3 in the VPC and update the route tables.
Establish an AWS Direct Connect connection to access S3.
Use AWS VPN to encrypt the traffic between the VPC and S3.
75 questions · hints · full answers · grading