Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon MLA-C01 Exam - Topic 3 Question 21 Discussion

A company is planning to use Amazon Redshift ML in its primary AWS account. The source data is in an Amazon S3 bucket in a secondary account.An ML engineer needs to set up an ML pipeline in the primary account to access the S3 bucket in the secondary account. The solution must not require public IPv4 addresses.Which solution will meet these requirements?
D) Provision a Redshift cluster and Amazon SageMaker Studio in a VPC in the primary account. Create an S3 gateway endpoint. Update the S3 bucket policy to allow IAM principals from the primary account. Set up interface VPC endpoints for SageMaker and Amazon Redshift.
A) Provision a Redshift cluster and Amazon SageMaker Studio in a VPC with no public access enabled in the primary account. Create a VPC peering connection between the accounts. Update the VPC route tables to remove the route to 0.0.0.0/0.
B) Provision a Redshift cluster and Amazon SageMaker Studio in a VPC with no public access enabled in the primary account. Create an AWS Direct Connect connection and a transit gateway. Associate the VPCs from both accounts with the transit gateway. Update the VPC route tables to remove the route to 0.0.0.0/0.
C) Provision a Redshift cluster and Amazon SageMaker Studio in a VPC in the primary account. Create an AWS Site-to-Site VPN connection with two encrypted IPsec tunnels between the accounts. Set up interface VPC endpoints for Amazon S3.

Amazon MLA-C01 Exam - Topic 3 Question 21 Discussion

Actual exam question for Amazon's MLA-C01 exam
Question #: 21
Topic #: 3
[All MLA-C01 Questions]

A company is planning to use Amazon Redshift ML in its primary AWS account. The source data is in an Amazon S3 bucket in a secondary account.

An ML engineer needs to set up an ML pipeline in the primary account to access the S3 bucket in the secondary account. The solution must not require public IPv4 addresses.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: D

S3 Gateway Endpoint: Allows private access to S3 from within a VPC without requiring a public IPv4 address, ensuring that data transfer between the primary and secondary accounts is secure and private.

Bucket Policy Update: The S3 bucket policy in the secondary account must explicitly allow access from the primary account's IAM principals to provide the necessary permissions.

Interface VPC Endpoints: Required for private communication between the VPC and Amazon SageMaker and Amazon Redshift services, ensuring the solution operates without public internet access.

This configuration meets the requirement to avoid public IPv4 addresses and allows secure and private communication between the accounts.


Contribute your Thoughts:

0/2000 characters
Lyda
2 days ago
Wait, can you really set up a gateway endpoint like that? Sounds too easy!
upvoted 0 times
...
Junita
7 days ago
I agree, D is definitely the most straightforward approach here.
upvoted 0 times
...
Sabrina
12 days ago
Option D seems like the simplest solution for accessing S3 without public IPs.
upvoted 0 times
...
Dacia
17 days ago
I believe option C is the right choice since it talks about setting up VPC endpoints, but I’m not entirely confident.
upvoted 0 times
...
Candra
22 days ago
I’m a bit confused about the difference between a transit gateway and a VPN connection. I feel like I’ve seen questions like this before.
upvoted 0 times
...
Margo
28 days ago
I think option D sounds familiar because it mentions S3 gateway endpoints, which we practiced in class.
upvoted 0 times
...
Pamella
1 month ago
I remember something about VPC peering, but I'm not sure if it works with S3 access across accounts.
upvoted 0 times
...

Save Cancel