AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsHard

A global media company operates a content management system (CMS) that stores large media files (up to several terabytes each) in Amazon S3. The CMS frequently needs to generate pre-signed URLs for users to securely upload and download these large files directly to/from S3, bypassing the CMS application server to improve performance and reduce load. However, generating these URLs for very large objects, especially for uploads, often exceeds typical HTTP request timeouts or requires complex multi-part upload logic within the application. The company wants to optimize this process, ensuring secure, efficient, and reliable direct upload/download of large files. Which approach should the Solutions Architect recommend to improve this process?

  1. ARoute all uploads and downloads through an Amazon EC2 instance running NGINX as a reverse proxy.
  2. BGenerate pre-signed URLs with S3 Transfer Acceleration enabled for uploads and downloads.
  3. CImplement S3 pre-signed URLs for downloads and use the S3 Multi-Part Upload API with pre-signed URLs for uploads.
  4. DUse Amazon CloudFront with signed URLs for both uploads and downloads.
Show answer & explanation

Correct answer: C. Implement S3 pre-signed URLs for downloads and use the S3 Multi-Part Upload API with pre-signed URLs for uploads.

For downloads, S3 pre-signed URLs are sufficient. For very large uploads, the S3 Multi-Part Upload API, combined with pre-signed URLs for each part, is the most robust and efficient method. It allows uploads to be broken into smaller, manageable chunks, which can be uploaded in parallel, resumed, and individually authenticated, addressing timeout and reliability issues for large files.

Why the other options are wrong

  • A. Routing through an EC2 instance defeats the purpose of direct S3 access, reintroduces the application server as a bottleneck, and increases operational overhead, leading to the same performance and scalability issues the company wants to avoid.
  • B. S3 Transfer Acceleration can speed up transfers but doesn't fundamentally address the complexity of large file uploads or the need to manage multi-part logic within the application itself when using standard pre-signed URLs for the entire object.
  • D. CloudFront signed URLs are primarily for secure *downloads* (access to cached content), not typically for direct uploads to S3, especially for multi-part uploads.

S3 Pre-signed URLs with Multi-Part Upload

A method to securely allow users to directly upload or download objects to/from Amazon S3 without exposing AWS credentials, with Multi-Part Upload specifically optimizing large file uploads for efficiency and reliability.

  • Pre-signed URLs grant temporary access to S3 objects.
  • Multi-Part Upload breaks large files into smaller parts for parallel upload.
  • Combining them allows secure, resumable, and efficient large file uploads directly to S3.

Memory trick: Pre-signed URLs are your temporary key, Multi-Part is how you break the big package into smaller, faster deliveries.

More Continuously Improve Existing Solutions questions