Full AWS Practitioner Certification Question

A software company is running a Java Spring Boot application inside an Amazon EKS pod within private subnets of a VPC. The application needs to write records to an Amazon DynamoDB table. For security reasons, the traffic must not traverse the public internet. A solutions architect is tasked with ensuring that the application can securely connect to DynamoDB without violating network or identity best practices.Which combination of steps should the architect implement to meet these requirements? (Select two.)