nerdexam
AmazonAmazon

SAA-C03 · Question #266

SAA-C03 Question #266: Real Exam Question with Answer & Explanation

Sign in or unlock SAA-C03 to reveal the answer and full explanation for question #266. The question stem and answer options stay visible for context.

Submitted by eva_at· Mar 4, 2026Design Secure Architectures

Question

An internal product team is deploying a new application to a private VPC in a company's AWS account. The application runs on Amazon EC2 instances that are in a security group named App1. The EC2 instances store application data in an Amazon S3 bucket and use AWS Secrets Manager to store application service credentials. The company's security policy prohibits applications in a private VPC from using public IP addresses to communicate. Which combination of solutions will meet these requirements? (Select TWO.)

Options

  • AConfigure gateway endpoints for Amazon S3 and AWS Secrets Manager.
  • BConfigure interface VPC endpoints for Amazon S3 and AWS Secrets Manager.
  • CAdd routes to the endpoints in the VPC route table.
  • DAssociate the App1 security group with the interface VPC endpoints. Configure a self-referencing
  • EAssociate the App1 security group with the gateway endpoints. Configure a self-referencing

Unlock SAA-C03 to see the answer

You've previewed enough free SAA-C03 questions. Unlock SAA-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SAA-C03 PracticeBrowse All SAA-C03 Questions