ETExamTower
Q16Network Security, Compliance, and Governance

A company’s data center connects to a single AWS Region through an AWS Direct Connect dedicated connection. The company has one VPC in that Region and stores logs for all its applications locally in the data center. The company must retain all application logs for 7 years. It decides to copy all application logs to an Amazon S3 bucket. Which solution meets these requirements?

← → navigate · a answer
Community votes
C
50% (5)
B
40% (4)
A
10% (1)
D
0% (0)
Discussion · 12
A 4
How about (A) that has an S3 gateway (preferred as free) endpoint providing S3 for inside the VPC and the public VIF providing S3 service for the DC across DX.
C 4
C: because gateway endpoints are not accessible from sources outside the VPC (like DX)
B 3
I pick B. All options can access S3. GW endpoint is free but interface endpoint isn't. Security wise we will pick private VIF not public VIF, and pick GW endpoint not interface endpoint.
C 3
https://docs.aws.amazon.com/AmazonS3/latest/userguide/privatelink-interface-endpoints.html you allow in-VPC applications to continue accessing Amazon S3 through the gateway endpoint, which is not billed. Then, only your on-premises applications would use interface endpoints to access Amazon S3.
2
Private VIF doesn't provide S3 to onprem ?
C 2
Private VIF - Used to access VPC resources (including VPC endpoints) over private IPs from on-premises. Interface endpoints for Amazon S3 - Allow access from on premises
C 2
Interface Endpoint for Amazon S3: Unlike gateway endpoints, interface endpoints (using AWS PrivateLink) are accessible from both inside the VPC and from external sources such as an AWS Direct Connect connection or VPN. This makes the interface endpoint the right choice when the application logs stored locally in the data center need to be uploaded to S3 over the Direct Connect connection.
1
The Q doesn't say that the Direct Connect was set up using private addressing, can we default to thinking that private addressing is in place?
B 1
Private Virtual Interface (VIF): A private VIF is used to access AWS services like Amazon S3 through your VPC. It enables private connectivity between your on-premises data center and your VPC over Direct Connect. S3 Gateway Endpoint: This is the appropriate endpoint type for Amazon S3. Gateway endpoints are the recommended way to connect to S3 from a VPC as they use route tables to direct traffic over the AWS private network to S3 without traversing the internet.
B 1
B is no doubt the correct answer. S3 Gateway Endpoint An S3 Gateway Endpoint allows traffic from within the VPC to reach S3 without traversing the internet, at no additional cost Since the on-premises data arrives via the Private VIF into the VPC, the gateway endpoint allows that traffic to then reach S3 privately It is the recommended and cost-effective method for S3 access from a VPC
1
Cant use gateway endpoints over DX; it's a route table entry. Theres no ENI in the VCP to route to; it needs an interface + private VIF (in this scenario).
B 1
vote B