Secure Redshift Spectrum Access with VPC Endpoints
A finance company uses Amazon Redshift as a data warehouse. The company stores the data in a shared Amazon S3 bucket. The company uses Amazon Redshift Spectrum to access the data that is stored in the S3 bucket. The data comes from certified third-party data providers. Each third-party data provider has unique connection details. To comply with regulations, the company must ensure that none of the data is accessible from outside the company's AWS environment. Which combination of steps should the company take to meet these requirements? (Choose two.)
Community Votes
45% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The trap is assuming NAT Gateway provides sufficient isolation for S3 access; in reality, Enhanced VPC Routing combined with Interface VPC Endpoints is required to force traffic through private links.
This question tests securing Amazon Redshift Spectrum access to S3 using VPC endpoints and enhanced VPC routing. The correct steps ensure data remains within the AWS network boundary.
Many candidates choose AE, believing Federated Queries eliminate the need for S3 storage. However, the scenario explicitly states data IS stored in S3, making E invalid as it contradicts the premise.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A is correct because placing the cluster in a private subnet and using an Interface VPC Endpoint (PrivateLink) ensures that management and query traffic never traverse the public internet. Although the option mentions a NAT Gateway, this is technically necessary if the Redshift cluster needs to download software updates or connect to other public AWS services while remaining unexposed to inbound internet traffic. Option C is correct because turning on Enhanced VPC Routing forces all Spectrum queries (which go to S3) to travel over the VPC's network interfaces rather than the default route table, allowing them to be routed through VPC Endpoints.Why the Other Options Are Wrong
Option B (CloudHSM) addresses encryption key management, not network access control or data exfiltration prevention. Option D (Table Constraints) enforces data integrity but has no impact on network security or external accessibility. Option E suggests using Federated Queries and NOT uploading data to S3, which directly contradicts the scenario stating 'The company stores the data in a shared Amazon S3 bucket.' Furthermore, Gateway VPC Endpoints are only available for S3 and DynamoDB, not for generic federated query connections to arbitrary third-party databases.Community Comment Notes
Several users like kailu and BigMrT argued for E, citing that Federated Queries reduce attack surface. However, as noted by hk0308, none of the answers perfectly satisfy every constraint without some technical nuance, but A and C are the standard architectural patterns for isolating Redshift Spectrum. User paali correctly questioned the use of NAT GW, highlighting the confusion between NAT (outbound only) and Gateway Endpoints (S3 specific). The consensus among experts is that A and C represent the intended security posture of keeping traffic within the VPC.Exam Strategy
Always read the scenario constraints carefully. If the prompt says data is in S3, do not choose an answer that says 'do not upload to S3'. Look for keywords like 'outside the company's AWS environment' which point towards VPC Endpoints and PrivateLink.
Frequently Asked Questions
Why is a NAT Gateway included in Option A if we want to block external access?
NAT Gateways allow outbound internet access for instances in private subnets (e.g., for software updates) without exposing them to inbound traffic. It does not violate the requirement of preventing external access to the data.
Why can't we use Federated Queries (Option E) instead?
The scenario explicitly states the company stores data in S3. Option E says 'Do not upload the data to the S3 bucket,' which contradicts the business requirement described in the question.
Related Analysis
Practice All DEA-C01 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DEA-C01 Practice Test →