A company configured a gateway VPC endpoint for Amazon S3 in a VPC. Only one subnet in the VPC uses the endpoint by routing S3 traffic through it. The VPC also has an internet gateway. From an Amazon EC2 instance in that subnet, a security engineer tries to use the instance profile credentials to retrieve an object from an S3 bucket, but the request fails. The instance profile permissions, S3 bucket policy, security group, and network ACLs have all been verified as correct. What else should the security engineer check to determine why the request is failing?
Choose an answer
Tap an option to check your answer.
Correct answer: Verify that the VPC endpoint policy allows access to Amazon S3..
Why this is the answer
The correct answer is to verify the VPC endpoint policy. When using a gateway VPC endpoint for S3, an endpoint policy controls what S3 actions and resources can be accessed through that endpoint. Even if the instance profile, bucket policy, security groups, and NACLs are correct, a restrictive endpoint policy can still block access. Incorrect options: An EC2 instance's security group does not have implicit inbound deny rules for S3; S3 is an outbound connection. VPC endpoint security groups do not control inbound traffic from EC2 instances; they control traffic to the endpoint itself. The internet gateway is irrelevant if the EC2 instance is routing S3 traffic through the VPC endpoint. The endpoint provides private connectivity, bypassing the internet gateway for S3.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed