nerdexam
Amazon

DBS-C01 · Question #334

A database administrator is reviewing the deployment of an application that uses Amazon DynamoDB. A fleet of Amazon EC2 application instances accesses the database. The database administrator notices

Sign in or unlock DBS-C01 to reveal the answer and full explanation for question #334. The question stem and answer options stay visible for context.

Submitted by manish99· Mar 6, 2026Database Security

Question

A database administrator is reviewing the deployment of an application that uses Amazon DynamoDB. A fleet of Amazon EC2 application instances accesses the database. The database administrator notices that EC2 instances are using public IP addresses to access the database and that the database is available to the internet. Company policy requires that all corporate data must be accessed privately and that external access from the internet is not allowed. Which combination of steps will ensure that the DynamoDB database meets these requirements? (Choose two.)

Options

  • AConfigure the DynamoDB security group and network ACLs to block external access.
  • BCreate an AWS PrivateLink VPC endpoint for DynamoDUpdate the VPC route table.
  • CCreate a gateway VPC endpoint for DynamoDB. Update the VPC route table.
  • DProvision a NAT gateway to access DynamoDB. Update the VPC route table.
  • EUse the aws:sourceVpce condition for all the IAM roles that provision access to the table.

Unlock DBS-C01 to see the answer

You've previewed enough free DBS-C01 questions. Unlock DBS-C01 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#DynamoDB VPC endpoint (Gateway)#Private access#IAM policy conditions#Network security
Full DBS-C01 Practice