nerdexam
Amazon

SOA-C02 · Question #274

A global company handles a large amount of personally identifiable information (Pll) through an internal web portal. The company's application runs in a corporate data center that is connected to…

The correct answer is A. Provision an interface VPC endpoint for Amazon S3. Using the interface endpoint, applications in your on-premises data center can easily query S3 buckets over AWS Direct Connect or Site-to-Site VPN. https://aws.amazon.com/blogs/architecture/choosing-your-vpc-endpoint-strategy-for-amazon-s3/

Submitted by carter_n· Mar 30, 2026Networking and Content Delivery

Question

A global company handles a large amount of personally identifiable information (Pll) through an internal web portal. The company's application runs in a corporate data center that is connected to AWS through an AWS Direct Connect connection. The application stores the Pll in Amazon S3. According to a compliance requirement, traffic from the web portal to Amazon S3 must not travel across the internet. What should a SysOps administrator do to meet the compliance requirement?

Options

  • AProvision an interface VPC endpoint for Amazon S3.
  • BConfigure AWS Network Firewall to redirect traffic to the internal S3 address.
  • CModify the application to use the S3 path-style endpoint.
  • DSet up a range of VPC network ACLs to redirect traffic to the Internal S3 address.

How the community answered

(20 responses)
  • A
    70% (14)
  • B
    10% (2)
  • C
    5% (1)
  • D
    15% (3)

Explanation

Using the interface endpoint, applications in your on-premises data center can easily query S3 buckets over AWS Direct Connect or Site-to-Site VPN. https://aws.amazon.com/blogs/architecture/choosing-your-vpc-endpoint-strategy-for-amazon-s3/

Topics

#VPC endpoint#Direct Connect#S3 private access#compliance networking

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice