QuestionQ11

Security and Compliance

A company runs an application on on-premises devices in the company’s on-premises data center. The company uses an AWS Direct Connect connection between that data center and the company’s AWS account. During the initial setup of the on-premises devices and during application updates, the application must retrieve configuration files from an Amazon Elastic File System (Amazon EFS) file system.

All traffic from the on-premises devices to Amazon EFS must stay private and encrypted. The on-premises devices must adhere to the principle of least privilege for AWS access. The company’s DevOps team must be able to revoke access for one device without affecting the other devices.

Which combination of steps meets these requirements?

Choose two
Explanation

IAM Roles Anywhere uses X.509 certificates issued to workloads outside AWS to obtain temporary IAM credentials for a role. A role with the AmazonElasticFileSystemClientReadWriteAccess policy grants the needed EFS client permissions without distributing shared, long-term IAM user credentials; device-specific certificates allow one device’s ability to obtain credentials to be removed independently. The EFS mount helper in amazon-efs-utils establishes a TLS connection for EFS data in transit, encrypting the NFS traffic over the private network path. IAM Roles Anywhere overview EFS encryption in transit

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!