nerdexam
Amazon

SAA-C03 · Question #31

A company hosts its application on several Amazon EC2 instances inside a VPC. The company creates a dedicated Amazon S3 bucket for each customer to store their relevant information in Amazon S3. The…

The correct answer is A. Create a gateway endpoint for Amazon S3 that is attached to the VPC Update the IAM instance. The company needs EC2 instances within a VPC to securely access only their S3 buckets without traversing the public internet, minimizing operational overhead.

Submitted by carter_n· Mar 4, 2026Design Secure Architectures

Question

A company hosts its application on several Amazon EC2 instances inside a VPC. The company creates a dedicated Amazon S3 bucket for each customer to store their relevant information in Amazon S3. The company wants to ensure that the application running on EC2 instances can securely access only the S3 buckets that belong to the company's AWS account. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • ACreate a gateway endpoint for Amazon S3 that is attached to the VPC Update the IAM instance
  • BCreate a NAT gateway in a public subnet with a security group that allows access to only Amazon
  • CCreate a gateway endpoint for Amazon S3 that is attached to the VPC Update the IAM instance
  • DCreate a NAT Gateway in a public subnet Update route tables to use the NAT Gateway Assign

How the community answered

(20 responses)
  • A
    80% (16)
  • B
    5% (1)
  • C
    10% (2)
  • D
    5% (1)

Why each option

The company needs EC2 instances within a VPC to securely access only their S3 buckets without traversing the public internet, minimizing operational overhead.

ACreate a gateway endpoint for Amazon S3 that is attached to the VPC Update the IAM instanceCorrect

An S3 gateway endpoint allows EC2 instances within a VPC to securely access S3 buckets without requiring an internet gateway or NAT device, keeping traffic within the Amazon network. This endpoint can be configured with a VPC endpoint policy to restrict access to specific S3 buckets owned by the company's AWS account, fulfilling the security requirement while significantly reducing operational overhead.

BCreate a NAT gateway in a public subnet with a security group that allows access to only Amazon

A NAT Gateway routes traffic to the public internet, which is not necessary for internal S3 access via a gateway endpoint and would incur higher costs and more complex security group management.

CCreate a gateway endpoint for Amazon S3 that is attached to the VPC Update the IAM instance
DCreate a NAT Gateway in a public subnet Update route tables to use the NAT Gateway Assign

Concept tested: S3 Gateway Endpoints for secure, private access

Source: https://docs.aws.amazon.com/vpc/latest/userguide/vpc-endpoints-s3.html

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice