ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 243 - SCS-C01 discussion

Report
Export

You have an Ec2 Instance in a private subnet which needs to access the KMS service. Which of the following methods can help fulfil this requirement, keeping security in perspective Please select:

A.
Use a VPC endpoint
Answers
A.
Use a VPC endpoint
B.
Attach an Internet gateway to the subnet
Answers
B.
Attach an Internet gateway to the subnet
C.
Attach a VPN connection to the VPC
Answers
C.
Attach a VPN connection to the VPC
D.
Use VPC Peering
Answers
D.
Use VPC Peering
Suggested answer: A

Explanation:

The AWS Documentation mentions the following

You can connect directly to AWS KMS through a private endpoint in your VPC instead of connecting over the internet. When you use a VPC endpoint communication between your VPC and AWS KMS is conducted entirely within the AWS network.

Option B is invalid because this could open threats from the internet Option C is invalid because this is normally used for communication between on-premise environments and AWS. Option D is invalid because this is normally used for communication between VPCs For more information on accessing KMS via an endpoint, please visit the following URL https://docs.aws.amazon.com/kms/latest/developerguide/kms-vpc-endpoint.htmllThe correct answer is: Use a VPC endpoint Submit your Feedback/Queries to our Experts

asked 16/09/2024
giorgi durglishvili
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first