When creating a OneLake shortcut to Amazon S3, authentication uses the standard AWS access key ID + secret access key pair. SAS token is for Azure Storage, not AWS. Certificate thumbprint is not used for S3. Access ID is incorrect naming; the correct term is access key ID. Correct answers: B and D. Reference: Create shortcuts to Amazon S3 in OneLake