Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SAP-C02 Topic 8 Question 40 Discussion

Actual exam question for Amazon's SAP-C02 exam
Question #: 40
Topic #: 8
[All SAP-C02 Questions]

A company has many AWS accounts and uses AWS Organizations to manage all of them. A solutions architect must implement a solution that the company can use to share a common network across multiple accounts.

The company's infrastructure team has a dedicated infrastructure account that has a VPC. The infrastructure team must use this account to manage the network. Individual accounts cannot have the ability to manage their own networks. However, individual accounts must be able to create AWS resources within subnets.

Which combination of actions should the solutions architect perform to meet these requirements? (Select TWO.)

Show Suggested Answer Hide Answer
Suggested Answer: C

Store the PGP Private Key:

Step 1: In the AWS Management Console, navigate to AWS Secrets Manager.

Step 2: Store the PGP private key in Secrets Manager. Ensure the key is encrypted and properly secured.

Set Up the Transfer Family Managed Workflow:

Step 1: In the AWS Transfer Family console, create a new managed workflow.

Step 2: Add a nominal step to the workflow that includes the decryption of the files. Configure this step with the PGP decryption parameters, referencing the PGP private key stored in Secrets Manager.

Step 3: Associate this workflow with the Transfer Family SFTP server, ensuring that incoming files are automatically decrypted upon receipt.

This solution ensures that the data is securely decrypted as it is transferred from the SFTP server to the S3 bucket, automating the decryption process and leveraging AWS Secrets Manager for key management.

Reference

AWS Transfer Family Documentation

Using AWS Secrets Manager for Managing Secrets

AWS Transfer Family Managed Workflows


Contribute your Thoughts:

Nichelle
25 days ago
Wait, so the individual accounts can't manage their own networks? That's like being a grown-up and still having your parents tell you how to tie your shoes. *sigh* Anyway, B and D it is.
upvoted 0 times
Elizabeth
9 days ago
Yeah, it's like having your hands tied. But B and D seem like the way to go.
upvoted 0 times
...
...
Alecia
1 months ago
Haha, imagine the poor infrastructure team having to manage the network for all the individual accounts. No thanks, I'll take the easy way out with B and D!
upvoted 0 times
I agree, B and D seem like the most efficient options to share the network across multiple accounts.
upvoted 0 times
...
Eden
3 days ago
D) Create a resource share in AWS Resource Access Manager in the infrastructure account. Select the specific AWS Organizations OU that will use the shared network. Select each subnet to associate with the resource share.
upvoted 0 times
...
Cassie
15 days ago
B) Enable resource sharing from the AWS Organizations management account.
upvoted 0 times
...
...
Ahmed
1 months ago
I agree with Tanja. Option C sounds like a lot of manual work, and E doesn't seem relevant to the problem statement.
upvoted 0 times
...
Delisa
2 months ago
I believe we should create VPCs in each AWS account within the organization and peer them with the VPC in the infrastructure account.
upvoted 0 times
...
Adelle
2 months ago
I agree with that. We also need to enable resource sharing from the AWS Organizations management account.
upvoted 0 times
...
Tanja
2 months ago
Option B and D seem like the way to go. Enabling resource sharing from the organization account and creating a resource share in the infrastructure account should do the trick.
upvoted 0 times
Janessa
7 days ago
E) Create a resource share in AWS Resource Access Manager in the infrastructure account. Select the specific AWS Organizations OU that will use the shared network. Select each prefix list to associate with the resource share.
upvoted 0 times
...
Jeanice
15 days ago
That sounds like a solid plan. Sharing resources from the organization account and setting up a resource share in the infrastructure account should work well.
upvoted 0 times
...
Arlean
1 months ago
D) Create a resource share in AWS Resource Access Manager in the infrastructure account. Select the specific AWS Organizations OU that will use the shared network. Select each subnet to associate with the resource share.
upvoted 0 times
...
Aretha
1 months ago
B) Enable resource sharing from the AWS Organizations management account.
upvoted 0 times
...
...
William
2 months ago
I think we should create a transit gateway in the infrastructure account.
upvoted 0 times
...

Save Cancel