A company needs to allow an EC2 instance to access an Amazon S3 bucket securely without sending traffic over the public internet. Which option achieves this?
Choose an answer
Tap an option to check your answer.
Correct answer: VPC endpoint.
Why this is the answer
A VPC endpoint allows private connectivity from your Amazon Virtual Private Cloud (VPC) to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect. For Amazon S3, a gateway endpoint is used, which acts as a target for a route in your route table. This ensures traffic to S3 stays within the AWS network and doesn't traverse the public internet. A VPN connection would involve routing traffic over a public network, which is not what the question asks for. An internet gateway allows instances to connect to the internet, which is the opposite of the requirement. A NAT gateway allows instances in a private subnet to connect to the internet or other AWS services, but it still involves routing through a NAT device and potentially over the public internet for S3 access without a VPC endpoint.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed