Courseiva
Data Store Management →mediumMultiple Choice

DEA-C01 Data Store Management Practice Question

A data engineer is deploying an Amazon Redshift cluster that must be accessible only from within a private VPC and must not have a public IP address. The cluster will be queried by an Amazon EMR cluster in the same VPC and by on-premises BI tools over a VPN connection. Which configuration should the engineer choose?

⚠ Common exam trap

The trap here is assuming that placing a cluster in a private subnet automatically disables public accessibility, when the publicly accessible setting must be explicitly turned off to avoid a public IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Launch the Redshift cluster with the publicly accessible setting disabled and attach it to a private subnet group.

To ensure a Redshift cluster has no public IP and is reachable only privately, the engineer must disable the publicly accessible setting and use a private subnet group. This prevents internet exposure while allowing access from within the VPC and over VPN. The other options either enable public access or do not explicitly disable it, failing the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Launch the Redshift cluster in a private subnet group and configure an AWS Site-to-Site VPN connection to the VPC.

    Why it's wrong here

    A private subnet group alone does not disable public accessibility; the cluster could still receive a public IP if the publicly accessible setting is enabled. The VPN connection is already assumed in the scenario for on-premises access. This option does not explicitly disable the public IP, so it fails the requirement.

  • ✗

    Launch the Redshift cluster with the publicly accessible setting enabled and attach it to a public subnet group.

    Why it's wrong here

    Enabling public accessibility assigns a public IP address to the cluster, which violates the requirement that it must not have a public IP. Even with security groups, the cluster would be reachable from the internet, increasing the attack surface. This configuration does not satisfy the private-only access requirement.

  • ✗

    Launch the Redshift cluster with the publicly accessible setting disabled and attach it to a public subnet group.

    Why it's wrong here

    A public subnet group is used for clusters that require a public IP, such as when using the public internet for client connections. Even with public accessibility disabled, placing the cluster in a public subnet group is unnecessary and may expose it to unintended routing. Private subnet groups are the correct choice for private-only clusters.

  • ✓

    Launch the Redshift cluster with the publicly accessible setting disabled and attach it to a private subnet group.

    Why this is correct

    Disabling the publicly accessible setting prevents the cluster from receiving a public IP address. Placing it in a private subnet group ensures that only resources within the VPC, such as the EMR cluster, and connected networks over VPN can reach it. This meets the requirement for private-only access without exposing the cluster to the internet.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.