New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SAA-C03 Exam - Topic 3 Question 41 Discussion

Actual exam question for Amazon's SAA-C03 exam
Question #: 41
Topic #: 3
[All SAA-C03 Questions]

A company has two AWS accounts: Production and Development. The company needs to push code changes in the Development account to the Production account. In the alpha phase, only two senior developers on the development team need access to the Production account. In the beta phase, more developers will need access to perform testing.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B

This solution meets the requirements most cost-effectively because it enables the company to migrate its on-premises NFS data store to AWS without changing the existing applications or workflows. AWS Storage Gateway is a hybrid cloud storage service that provides seamless and secure integration between on-premises and AWS storage. Amazon S3 File Gateway is a type of AWS Storage Gateway that provides a file interface to Amazon S3, with local caching for low-latency access. By setting up an Amazon S3 File Gateway, the company can store and retrieve files as objects in Amazon S3 using standard file protocols such as NFS. The company can also use an Amazon S3 Lifecycle policy to automatically transition the data to the appropriate storage class based on the frequency of access and the cost of storage. For example, the company can use S3 Standard for frequently accessed data, S3 Standard-Infrequent Access (S3 Standard-IA) or S3 One Zone-Infrequent Access (S3 One Zone-IA) for less frequently accessed data, and S3 Glacier or S3 Glacier Deep Archive for long-term archival data.

Option A is not a valid solution because AWS Storage Gateway Volume Gateway is a type of AWS Storage Gateway that provides a block interface to Amazon S3, with local caching for low-latency access. Volume Gateway is not suitable for migrating an NFS data store, as it requires attaching the volumes to EC2 instances or on-premises servers using the iSCSI protocol. Option C is not a valid solution because Amazon Elastic File System (Amazon EFS) is a fully managed elastic NFS file system that is designed for workloads that require high availability, scalability, and performance. Amazon EFS Standard-Infrequent Access (Standard-IA) is a storage class within Amazon EFS that is optimized for infrequently accessed files, with a lower price per GB and a higher price per access. Using Amazon EFS Standard-IA for migrating an NFS data store would not be cost-effective, as it would incur higher access charges and require additional configuration to enable lifecycle management. Option D is not a valid solution because Amazon EFS One Zone-Infrequent Access (One Zone-IA) is a storage class within Amazon EFS that is optimized for infrequently accessed files that do not require the availability and durability of Amazon EFS Standard or Standard-IA. Amazon EFS One Zone-IA stores data in a single Availability Zone, which reduces the cost by 47% compared to Amazon EFS Standard-IA, but also increases the risk of data loss in the event of an Availability Zone failure. Using Amazon EFS One Zone-IA for migrating an NFS data store would not be cost-effective, as it would incur higher access charges and require additional configuration to enable lifecycle management. It would also compromise the availability and durability of the data.


AWS Storage Gateway - Amazon Web Services

Amazon S3 File Gateway - AWS Storage Gateway

Object Lifecycle Management - Amazon Simple Storage Service

[AWS Storage Gateway Volume Gateway - AWS Storage Gateway]

[Amazon Elastic File System - Amazon Web Services]

[Using EFS storage classes - Amazon Elastic File System]

Contribute your Thoughts:

0/2000 characters
Cristen
3 months ago
I didn’t know you could set up roles like that, sounds complicated!
upvoted 0 times
...
Elena
3 months ago
B is definitely the way to go, assuming roles is a best practice.
upvoted 0 times
...
Rolande
3 months ago
Wait, why not just use IAM groups? D sounds simpler!
upvoted 0 times
...
Francene
4 months ago
I disagree, C might be more secure with the trust policy in Production.
upvoted 0 times
...
Shannan
4 months ago
Option B seems like the best choice for cross-account access.
upvoted 0 times
...
Maile
4 months ago
I feel like option A is too simplistic for the requirements. It doesn't seem to cover the need for controlled access during both phases.
upvoted 0 times
...
Julianna
4 months ago
I'm a bit confused about the differences between options C and D. They both mention IAM roles and trust policies, but I can't recall which one is more appropriate.
upvoted 0 times
...
Nilsa
4 months ago
I remember practicing a question similar to this, and I feel like option C might be the right approach since it involves a trust policy.
upvoted 0 times
...
Margot
5 months ago
I think option B sounds familiar, but I'm not entirely sure if it’s the best choice for this scenario.
upvoted 0 times
...
Destiny
5 months ago
I'm pretty confident that option B is the right answer here. Creating the IAM role in the Development account and allowing developers to assume it is the most flexible and scalable solution that meets the requirements.
upvoted 0 times
...
Latia
5 months ago
Okay, I think I've got it. Option B seems like the best solution - we create an IAM role in the Development account and grant it access to the Production account. Then we can allow the developers to assume that role. That way, we can control access centrally and easily add more developers in the beta phase.
upvoted 0 times
...
Selene
5 months ago
This looks like a classic IAM permissions management question. I think the key is to understand the requirements - we need to grant access to the Production account from the Development account, but only for a limited set of developers initially.
upvoted 0 times
...
Terrilyn
5 months ago
Hmm, I'm a bit confused by the wording here. Are we supposed to create the IAM role in the Development account or the Production account? I'm not sure which option is the best approach.
upvoted 0 times
...
Mel
5 months ago
Ah, I think I know the answer to this. Cisco DNA Center is their flagship network management and analytics platform. It sounds like the description in the question matches that product.
upvoted 0 times
...
Raelene
5 months ago
This is a tricky one, but I think I can work it out. I'll start by eliminating the obvious cloud-based options, then focus on the more on-premises architectures. The multi-tier system on a single computer seems like the most likely candidate that fits the criteria.
upvoted 0 times
...
Staci
9 months ago
I'm picturing the senior devs logging into the Production account like secret agents, all stealthy-like. Option B is the spy-approved solution!
upvoted 0 times
Vincenza
8 months ago
Once the beta phase starts, we can easily add more developers to the access list with Option B.
upvoted 0 times
...
Reta
8 months ago
I agree, Option B sounds like the best way to handle access for the senior developers.
upvoted 0 times
...
Adolph
9 months ago
Option B: Use AWS Organizations to create a service control policy that allows the senior developers from the Development account to assume roles in the Production account.
upvoted 0 times
...
Tyisha
9 months ago
Option A: Set up cross-account roles with permissions in the Production account for the two senior developers.
upvoted 0 times
...
...
Belen
9 months ago
You know, I was tempted by Option D at first, but then I realized it would be a pain to manage all those groups and permissions. Option B is definitely the winner here.
upvoted 0 times
Susana
8 months ago
Once the beta phase starts, we can easily scale up access for more developers using Option B.
upvoted 0 times
...
Katina
8 months ago
I agree, Option B is the most efficient solution for granting access to the Production account.
upvoted 0 times
...
Kathryn
9 months ago
Option B allows for easy management of permissions and access for the senior developers in the alpha phase.
upvoted 0 times
...
...
Terry
10 months ago
Haha, I can just imagine the chaos if we gave all the developers direct access to the Production account. Option B keeps things nice and tidy.
upvoted 0 times
Kerry
9 months ago
Agreed, it's important to maintain security and control access to sensitive environments like Production.
upvoted 0 times
...
Britt
9 months ago
That sounds like a good plan. We definitely don't want all developers having direct access to the Production account.
upvoted 0 times
...
Jeff
9 months ago
Option B: Use AWS Organizations to create a service control policy that allows only the two senior developers access to the Production account during the alpha phase.
upvoted 0 times
...
...
Latonia
10 months ago
I agree, Option B seems like the best choice. Allowing developers to assume the role in the Development account is a more controlled approach than granting direct access.
upvoted 0 times
Otis
9 months ago
Agreed. It's important to have a controlled approach when granting access to sensitive environments like Production.
upvoted 0 times
...
Armanda
9 months ago
I think so too. Direct access to the Production account can be risky, especially during the alpha phase.
upvoted 0 times
...
Victor
10 months ago
Option B is definitely the way to go. It's more secure to have developers assume a role in the Development account.
upvoted 0 times
...
...
Nicholle
10 months ago
Option B is the way to go. It's the most flexible and secure solution, allowing us to manage access to the Production account from the Development account.
upvoted 0 times
Kimberely
8 months ago
It's important to have a secure solution in place for this process.
upvoted 0 times
...
Augustine
9 months ago
We can easily control who has access to the Production account from the Development account.
upvoted 0 times
...
Tamala
9 months ago
I agree, it provides the flexibility we need to manage access.
upvoted 0 times
...
Fausto
10 months ago
Option B is definitely the best choice for this scenario.
upvoted 0 times
...
...
Kimberlie
10 months ago
I'm not sure. Option C also seems like a valid solution. Creating an IAM role in the Production account could work too.
upvoted 0 times
...
Sabine
11 months ago
I agree with Bettina. Creating an IAM role in the Development account seems like the most secure way to handle access.
upvoted 0 times
...
Bettina
11 months ago
I think option B is the best solution.
upvoted 0 times
...

Save Cancel