nerdexam
Amazon

SAP-C02 · Question #8

A company has a data lake in Amazon S3 that needs to be accessed by hundreds of applications across many AWS accounts. The company's information security policy states that the S3 bucket must not be…

The correct answer is A. Create an S3 access point for each application in the AWS account that owns the S3 bucket. C. Create a gateway endpoint lor Amazon S3 in each application's VPC. App --> S3 Access Point --> S3 Gateway Endpoint --> S3 Bucket https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-

Submitted by kevin_r· Mar 6, 2026Design Secure Architectures

Question

A company has a data lake in Amazon S3 that needs to be accessed by hundreds of applications across many AWS accounts. The company's information security policy states that the S3 bucket must not be accessed over the public internet and that each application should have the minimum permissions necessary to function. To meet these requirements, a solutions architect plans to use an S3 access point that is restricted to specific VPCs tor each application. Which combination of steps should the solutions architect take to implement this solution? (Choose two.)

Options

  • ACreate an S3 access point for each application in the AWS account that owns the S3 bucket.
  • BCreate an interface endpoint for Amazon S3 in each application's VPC.
  • CCreate a gateway endpoint lor Amazon S3 in each application's VPC.
  • DCreate an S3 access point for each application in each AWS account and attach the access
  • ECreate a gateway endpoint for Amazon S3 in the data lake's VPC.

How the community answered

(39 responses)
  • A
    69% (27)
  • B
    3% (1)
  • D
    21% (8)
  • E
    8% (3)

Explanation

App --> S3 Access Point --> S3 Gateway Endpoint --> S3 Bucket https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice