exam questions

Exam AWS Certified Database - Specialty All Questions

View all questions & answers for the AWS Certified Database - Specialty exam

Exam AWS Certified Database - Specialty topic 1 question 250 discussion

Exam question from Amazon's AWS Certified Database - Specialty
Question #: 250
Topic #: 1
[All AWS Certified Database - Specialty Questions]

A pharmaceutical company uses Amazon Quantum Ledger Database (Amazon QLDB) to store its clinical trial data records. The company has an application that runs as AWS Lambda functions. The application is hosted in the private subnet in a VPC.
The application does not have internet access and needs to read some of the clinical data records. The company is concerned that traffic between the QLDB ledger and the VPC could leave the AWS network. The company needs to secure access to the QLDB ledger and allow the VPC traffic to have read-only access.
Which security strategy should a database specialist implement to meet these requirements?

  • A. Move the QLDB ledger into a private database subnet inside the VPC. Run the Lambda functions inside the same VPC in an application private subnet. Ensure that the VPC route table allows read-only flow from the application subnet to the database subnet.
  • B. Create an AWS PrivateLink VPC endpoint for the QLDB ledger. Attach a VPC policy to the VPC endpoint to allow read-only traffic for the Lambda functions that run inside the VPC.
  • C. Add a security group to the QLDB ledger to allow access from the private subnets inside the VPC where the Lambda functions that access the QLDB ledger are running.
  • D. Create a VPN connection to ensure pairing of the private subnet where the Lambda functions are running with the private subnet where the QLDB ledger is deployed.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mbar94
Highly Voted 2 years, 8 months ago
Selected Answer: B
I'd go with B - https://docs.aws.amazon.com/qldb/latest/developerguide/vpc-endpoints.html
upvoted 5 times
...
tsk9921
Most Recent 2 years ago
B...VPC endpoint is the AWS recommended way to connect services within VPC. For the req of keeping traffic private (avoid public internet) AWS PrivateLink is the option.
upvoted 2 times
...
examineme
2 years, 5 months ago
Selected Answer: B
AWS PrivateLink VPC endpoint
upvoted 2 times
...
rags1482
2 years, 6 months ago
Answer is B as per mbar94 link
upvoted 1 times
...
awsjjj
2 years, 6 months ago
Selected Answer: B
https://docs.aws.amazon.com/qldb/latest/developerguide/vpc-endpoints.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago