nerdexam
Amazon

ANS-C01 · Question #94

An organization wants to process sensitive information using the Amazon EMR service. The information is stored in on-premises databases. The output of processing will be encrypted using AWS KMS before

Sign in or unlock ANS-C01 to reveal the answer and full explanation for question #94. The question stem and answer options stay visible for context.

Submitted by saadiq_pk· Mar 6, 2026Network Design

Question

An organization wants to process sensitive information using the Amazon EMR service. The information is stored in on-premises databases. The output of processing will be encrypted using AWS KMS before it is uploaded to a customer-owned Amazon S3 bucket. The current configuration includes a VPS with public and private subnets, with VPN connectivity to the on- premises network. The security organization does not allow Amazon EC2 instances to run in the public subnet. What is the MOST simple and secure architecture that will achieve the organization's goal?

Options

  • AUse the existing VPC and configure Amazon EMR in a private subnet with an Amazon S3
  • BUse the existing VPS and a NAT gateway, and configure Amazon EMR in a private subnet with
  • CCreate a new VPS without an IGW and configure the VPN and Amazon EMR in a private subnet
  • DCreate a new VPS without an IGW and configure the VPN and Amazon EMR in a private subnet

Unlock ANS-C01 to see the answer

You've previewed enough free ANS-C01 questions. Unlock ANS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#EMR Networking#NAT Gateway#Hybrid Connectivity#S3 Encryption
Full ANS-C01 Practice