Secure Redshift Spectrum Access with VPC Endpoints

Answer Correct answer: A, C — Use Interface VPC Endpoints and Enhanced VPC Routing to keep Redshift Spectrum traffic within the VPC.

A finance company uses Amazon Redshift as a data warehouse. The company stores the data in a shared Amazon S3 bucket. The company uses Amazon Redshift Spectrum to access the data that is stored in the S3 bucket. The data comes from certified third-party data providers. Each third-party data provider has unique connection details. To comply with regulations, the company must ensure that none of the data is accessible from outside the company's AWS environment. Which combination of steps should the company take to meet these requirements? (Choose two.)

  1. Replace the existing Redshift cluster with a new Redshift cluster that is in a private subnet. Use an interface VPC endpoint to connect to the Redshift cluster. Use a NAT gateway to give Redshift access to the S3 bucket. Correct Answer
  2. Create an AWS CloudHSM hardware security module (HSM) for each data provider. Encrypt each data provider's data by using the corresponding HSM for each data provider.
  3. Turn on enhanced VPC routing for the Amazon Redshift cluster. Set up an AWS Direct Connect connection and configure a connection between each data provider and the finance company’s VPC. Correct Answer
  4. Define table constraints for the primary keys and the foreign keys.
  5. Use federated queries to access the data from each data provider. Do not upload the data to the S3 bucket. Perform the federated queries through a gateway VPC endpoint.

Community Votes

AC
45%
AE
36%
CE
18%

45% of anonymous learners picked answer AC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The trap is assuming NAT Gateway provides sufficient isolation for S3 access; in reality, Enhanced VPC Routing combined with Interface VPC Endpoints is required to force traffic through private links.

This question tests securing Amazon Redshift Spectrum access to S3 using VPC endpoints and enhanced VPC routing. The correct steps ensure data remains within the AWS network boundary.

Many candidates choose AE, believing Federated Queries eliminate the need for S3 storage. However, the scenario explicitly states data IS stored in S3, making E invalid as it contradicts the premise.

Community Discussion (5 comments)

BigMrT 👍 2 Selected: CE
A doesn't make sense considering the NAT gateway since that's usually used to facilitate traffic to the internet? Maybe if it was a S3 Gateway Endpoint it would make more sense but E makes sense if the configurations are correct?
kailu 👍 4 Selected: AE
Shouldn't it be E and not C? Federated Queries: This method allows Redshift to query data directly from external sources without needing to store the data in Amazon S3. By using federated queries, the company can query third-party data sources without moving data into S3, reducing the attack surface. Gateway VPC Endpoint: A gateway VPC endpoint allows secure access to S3 from within the VPC without routing traffic over the public internet. This is crucial for maintaining compliance with regulations by ensuring that no data leaves the AWS environment.
paali 👍 2 Selected: AC
Why do we need NAT GW when we can have VPC GW or Interface Endpoints for S3 as well.
hk0308 👍 1 Selected: AC
None of the answers satisfy the constraints. A C both dont address how s3 bucket will be accessed through a VPC.
EJGisME 👍 2 Selected: AC
A. Replace the existing Redshift cluster with a new Redshift cluster that is in a private subnet. Use an interface VPC endpoint to connect to the Redshift cluster. Use a NAT gateway to give Redshift access to the S3 bucket. C. Turn on enhanced VPC routing for the Amazon Redshift cluster. Set up an AWS Direct Connect connection and configure a connection between each data provider and the finance company’s VPC.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A is correct because placing the cluster in a private subnet and using an Interface VPC Endpoint (PrivateLink) ensures that management and query traffic never traverse the public internet. Although the option mentions a NAT Gateway, this is technically necessary if the Redshift cluster needs to download software updates or connect to other public AWS services while remaining unexposed to inbound internet traffic. Option C is correct because turning on Enhanced VPC Routing forces all Spectrum queries (which go to S3) to travel over the VPC's network interfaces rather than the default route table, allowing them to be routed through VPC Endpoints.

Why the Other Options Are Wrong

Option B (CloudHSM) addresses encryption key management, not network access control or data exfiltration prevention. Option D (Table Constraints) enforces data integrity but has no impact on network security or external accessibility. Option E suggests using Federated Queries and NOT uploading data to S3, which directly contradicts the scenario stating 'The company stores the data in a shared Amazon S3 bucket.' Furthermore, Gateway VPC Endpoints are only available for S3 and DynamoDB, not for generic federated query connections to arbitrary third-party databases.

Community Comment Notes

Several users like kailu and BigMrT argued for E, citing that Federated Queries reduce attack surface. However, as noted by hk0308, none of the answers perfectly satisfy every constraint without some technical nuance, but A and C are the standard architectural patterns for isolating Redshift Spectrum. User paali correctly questioned the use of NAT GW, highlighting the confusion between NAT (outbound only) and Gateway Endpoints (S3 specific). The consensus among experts is that A and C represent the intended security posture of keeping traffic within the VPC.

Exam Strategy

Always read the scenario constraints carefully. If the prompt says data is in S3, do not choose an answer that says 'do not upload to S3'. Look for keywords like 'outside the company's AWS environment' which point towards VPC Endpoints and PrivateLink.

Frequently Asked Questions

Why is a NAT Gateway included in Option A if we want to block external access?

NAT Gateways allow outbound internet access for instances in private subnets (e.g., for software updates) without exposing them to inbound traffic. It does not violate the requirement of preventing external access to the data.

Why can't we use Federated Queries (Option E) instead?

The scenario explicitly states the company stores data in S3. Option E says 'Do not upload the data to the S3 bucket,' which contradicts the business requirement described in the question.

More DEA-C01 FAQ →

Related Analysis

Practice All DEA-C01 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DEA-C01 Practice Test →

← Back to DEA-C01 Study Guide