Combine S3 Multi-Region Access Points with Direct Connect and PrivateLink

Answer Correct answers: A, E — Implement S3 Multi-Region Access Points and connect to them from on-premises using AWS Direct Connect with AWS PrivateLink.

A company operates a static content distribution platform that serves customers globally. The customers consume content from their own AWS accounts. The company serves its content from an Amazon S3 bucket. The company uploads the content from its on-premises environment to the S3 bucket by using an S3 File Gateway. The company wants to improve the platform’s performance and reliability by serving content from the AWS Region that is geographically closest to customers. The company must route the on-premises data to Amazon S3 with minimal latency and without public internet exposure. Which combination of steps will meet these requirements with the LEAST operational overhead? (Choose two.)

  1. Implement S3 Multi-Region Access Points Correct Answer
  2. Use S3 Cross-Region Replication (CRR) to copy content to different Regions
  3. Create an AWS Lambda function that tracks the routing of clients to Regions
  4. Use an AWS Site-to-Site VPN connection to connect to a Multi-Region Access Point.
  5. Use AWS PrivateLink and AWS Direct Connect to connect to a Multi-Region Access Point. Correct Answer

Community Votes

AE
62%
AB
19%
BE
19%

62% of anonymous learners picked answer AE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Multi-Region Access Points provide one global endpoint that routes to the nearest Region bucket, and Direct Connect with PrivateLink gives the on-premises environment a private path to that endpoint, so neither the uploads nor the reads touch the public internet.

A global static content platform is served from a single S3 bucket, uploaded from on-premises through an S3 File Gateway, and must serve customers from the geographically closest Region. On-premises traffic must reach S3 with minimal latency and no public internet exposure.

Adding a Site-to-Site VPN to a Multi-Region Access Point, or substituting Cross-Region Replication for the access point. A VPN still traverses the internet, and CRR only copies objects between Regions without providing a single closest-Region endpoint for the consumers to resolve.

Community Discussion (11 comments)

awsaz 👍 5 Selected: AE
A and E
nimbus_00 👍 1 Selected: BE
B and E. S3 Multi-Region Access Points Most Voted is mentioned in E anyway.
dv1 👍 1 Selected: BE
A+B+E is better for me tbh, but since we have to select 2 I go with B+E
0b43291 👍 1
Difficult one. Need E to protect traffic from onprem to AWS. Need A to access. However you would also need B to Sync the buckets across regions.
chris_spencer 👍 3 Selected: AB
A. Implement S3 Multi-Region Access Points and B. Use S3 Cross-Region Replication (CRR) to copy content to different Regions. The combination of (A) and (B) allows the company to serve content from the closest region to the end-user and ensures that the data is replicated across multiple regions to support this. Multi-Region Access Points simplify the access and management of the data while CRR ensures that the content is available across these regions. This setup provides a straightforward and managed solution to meet the requirement of geographical content routing with minimal operational overhead. For all that voting for E... how does AWS DirectConnect and "LEAST operational overhead" fit toghether.
JoeTromundo 👍 1 Selected: AE
A: S3 Multi-Region Access Points allow customers to access Amazon S3 data from multiple AWS Regions with the lowest latency. These access points automatically route requests to the closest region based on the user's location. This helps optimize performance and increases reliability by dynamically routing traffic to the most optimal region. E: AWS PrivateLink ensures private connectivity between AWS services and on-premises resources without traversing the public internet. B: Although CRR replicates data across Regions, it does NOT optimize performance by routing users to the closest Region dynamically. C: While Lambda can handle some routing logic, this option adds more operational overhead compared to using built-in features like S3 Multi-Region Access Points. D: It can't be because one of the requirements is "without public internet exposure."
Daniel76 👍 2 Selected: AE
The company wants to improve the platform’s performance and reliability by serving content from the AWS Region that is geographically closest to customers: s3 multi region access point. (A) The company must route the on-premises data to Amazon S3 with minimal latency and without public internet exposure: PrivateLink and Direct Connect to the MRAP. (E)
liuliangzhou 👍 1 Selected: BE
Option A: Multi regional access points are mainly used to access S3 data across multiple regions, rather than solving data transmission problems. Option B: Allows companies to automatically asynchronously replicate data from S3 buckets to S3 buckets in other AWS regions. Option E: AWS PrivateLink provides a secure and private way to access AWS services without using the public Internet.
vip2 👍 2 Selected: AE
A and E is correct to meet latency and private network
gfhbox0083 👍 2
A, E, for sure
kupo777 👍 2
A and B Multi-region access configuration allows content to be served from each region closest to the customer's AWS access using a cross-region replica of the AWS global network.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An S3 Multi-Region Access Point provides a single global endpoint that automatically routes each request to the bucket in the closest Region, which is exactly what the closest-Region serving requirement needs, and it works for both reads and writes. For the on-premises side, AWS Direct Connect gives a dedicated private connection into AWS and AWS PrivateLink lets that on-premises environment reach the Multi-Region Access Point privately, so the traffic never touches the public internet. These two options together cover the consumer routing and the private ingress path, and neither requires the company to operate routing logic or a Lambda function.

Why the Other Options Are Wrong

B: Cross-Region Replication copies objects to other Regions but it does not create a global endpoint, so consumers still have to resolve a Region-specific bucket endpoint and the company has to implement the closest-Region selection itself. C: A Lambda function tracking client routing to Regions is custom logic that has to be maintained and does not move the data path, so it adds overhead instead of removing it. D: A Site-to-Site VPN encrypts traffic across the public internet, which violates the requirement that the on-premises data must be routed to S3 without public internet exposure.

Community Comment Notes

The community was split three ways, with A and E the clear plurality at 63 votes and A plus B and B plus E tied behind at 19 each. Commenters agreed that E is mandatory because the on-premises side must avoid the public internet, and that A is the access point itself; one commenter noted that Cross-Region Replication would in practice also be needed to populate the second Region, but the question asks for the two steps that deliver the routing and private connectivity requirements.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide