A company needs to send data from on-premises systems privately (without traversing the internet) to Amazon S3 buckets that exist in three different AWS accounts. The company has no existing dedicated connectivity to AWS. Which combination of steps should a solutions architect recommend? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a networking account in AWS. Provision a private VPC in that networking account. Set up an AWS Direct Connect connection and create a private virtual interface (private VIF) between the on-premises environment and the private VPC., Create an Amazon S3 interface endpoint (AWS PrivateLink) in the networking account..
Why this is the answer
The correct options provide a secure, private, and scalable solution. A Direct Connect private VIF connects the on-premises environment directly to a VPC in a dedicated networking account, bypassing the public internet. This ensures private connectivity. An Amazon S3 interface endpoint (AWS PrivateLink) then allows private access to S3 buckets across multiple accounts via the Direct Connect connection, without traversing the internet. Using a public VIF with Direct Connect would expose traffic to the public internet, violating the privacy requirement. An S3 gateway endpoint is VPC-specific and cannot be shared across multiple accounts or used with PrivateLink for cross-account access in this scenario. VPC peering alone would not provide the necessary private access to S3 from on-premises without Direct Connect and an S3 endpoint.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed