Combine S3 Multi-Region Access Points with Direct Connect and PrivateLink
A company operates a static content distribution platform that serves customers globally. The customers consume content from their own AWS accounts. The company serves its content from an Amazon S3 bucket. The company uploads the content from its on-premises environment to the S3 bucket by using an S3 File Gateway. The company wants to improve the platform’s performance and reliability by serving content from the AWS Region that is geographically closest to customers. The company must route the on-premises data to Amazon S3 with minimal latency and without public internet exposure. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)
Community Votes
62% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Multi-Region Access Points provide one global endpoint that routes to the nearest Region bucket, and Direct Connect with PrivateLink gives the on-premises environment a private path to that endpoint, so neither the uploads nor the reads touch the public internet.
A global static content platform is served from a single S3 bucket, uploaded from on-premises through an S3 File Gateway, and must serve customers from the geographically closest Region. On-premises traffic must reach S3 with minimal latency and no public internet exposure.
Adding a Site-to-Site VPN to a Multi-Region Access Point, or substituting Cross-Region Replication for the access point. A VPN still traverses the internet, and CRR only copies objects between Regions without providing a single closest-Region endpoint for the consumers to resolve.
Community Discussion (11 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An S3 Multi-Region Access Point provides a single global endpoint that automatically routes each request to the bucket in the closest Region, which is exactly what the closest-Region serving requirement needs, and it works for both reads and writes. For the on-premises side, AWS Direct Connect gives a dedicated private connection into AWS and AWS PrivateLink lets that on-premises environment reach the Multi-Region Access Point privately, so the traffic never touches the public internet. These two options together cover the consumer routing and the private ingress path, and neither requires the company to operate routing logic or a Lambda function.Why the Other Options Are Wrong
B: Cross-Region Replication copies objects to other Regions but it does not create a global endpoint, so consumers still have to resolve a Region-specific bucket endpoint and the company has to implement the closest-Region selection itself. C: A Lambda function tracking client routing to Regions is custom logic that has to be maintained and does not move the data path, so it adds overhead instead of removing it. D: A Site-to-Site VPN encrypts traffic across the public internet, which violates the requirement that the on-premises data must be routed to S3 without public internet exposure.Community Comment Notes
The community was split three ways, with A and E the clear plurality at 63 votes and A plus B and B plus E tied behind at 19 each. Commenters agreed that E is mandatory because the on-premises side must avoid the public internet, and that A is the access point itself; one commenter noted that Cross-Region Replication would in practice also be needed to populate the second Region, but the question asks for the two steps that deliver the routing and private connectivity requirements.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →