Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer is configuring a VPC for an Amazon Redshift cluster. The cluster must be accessible only from a specific on-premises network via a Direct Connect connection. Which TWO actions should the engineer take to meet this requirement? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a security group to allow inbound traffic from the on-premises CIDR block.

Option B is correct because a security group acts as the stateful firewall for the Redshift cluster, and adding an inbound rule that permits the on-premises CIDR block on the Redshift port (5439) is required to allow that specific network to reach the cluster. Option C is correct because the network ACL is the stateless subnet-level control, so it must also include an inbound rule allowing the on-premises CIDR block (and corresponding outbound return traffic) for the connection to succeed. Option A is not needed because Enhanced VPC Routing only affects how COPY/UNLOAD traffic is routed to S3 or other services, not client access from on-premises. Option D is wrong because a VPC endpoint is for private access to AWS services like S3, not for enabling on-premises clients to reach a Redshift cluster. Option E is wrong because making the cluster publicly accessible would expose it to the internet, violating the requirement to restrict access to the on-premises network only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Redshift Enhanced VPC Routing.

    Why it's wrong here

    Enhanced VPC Routing only forces COPY and UNLOAD traffic through your VPC, so it governs where Redshift's own S3 and external data flows travel, not who may reach the cluster. It is tempting because it tightens network control around a cluster, but it would be the right choice when you must audit or restrict Redshift's data-loading paths, not for on-premises access.

  • ✓

    Configure a security group to allow inbound traffic from the on-premises CIDR block.

    Why this is correct

    A security group is stateful and instance-level, so allowing inbound traffic from the on-premises CIDR block restricts Redshift access to that network only, satisfying the requirement that the cluster be reachable solely via Direct Connect.

  • ✓

    Configure a network ACL to allow inbound traffic from the on-premises CIDR block.

    Why this is correct

    A network ACL is stateless and subnet-level, filtering inbound traffic from the on-premises CIDR block at the subnet boundary. Combined with a security group, it enforces that only the Direct Connect network can reach the Redshift cluster.

  • ✗

    Create a VPC endpoint for Redshift.

    Why it's wrong here

    A VPC endpoint (PrivateLink) exposes Redshift to resources inside the VPC or to other VPCs, not to an on-premises network reached over Direct Connect. It is tempting because it provides private connectivity without internet exposure, and would be correct for accessing Redshift from another VPC or AWS service.

  • ✗

    Make the Redshift cluster publicly accessible.

    Why it's wrong here

    Public accessibility assigns a public IP, letting the cluster be reached over the internet, which contradicts the requirement that access come only from the on-premises network via Direct Connect. It is tempting because it removes connectivity friction, and would be correct for clients connecting from outside the VPC without private links.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.