Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores sensitive user data in an S3 bucket. A Security Engineer needs to ensure that the EC2 instances can only access the specific S3 bucket and no other AWS services. Which solution meets these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an IAM role with a policy that grants s3:PutObject and s3:GetObject access to the specific bucket, and attach the role to the EC2 instances as an instance profile.

Creating an IAM role with a policy that grants s3:PutObject and s3:GetObject access only to the specific S3 bucket, and attaching that role to the EC2 instances as an instance profile, ensures that the instances can only access that bucket. This method uses AWS Identity and Access Management (IAM) to restrict permissions per resource. Option A is incorrect because an S3 bucket policy restricting access to the ALB's security group cannot control what the instances themselves do; the instances can still access S3 directly if they have credentials. Option C is incorrect because a VPC endpoint for S3 provides private connectivity but does not restrict which resources the instances can access; it only ensures traffic stays within the AWS network. Option D is incorrect because security groups cannot filter traffic based on S3 bucket names or policies; they only filter IP addresses and ports, and S3 uses HTTPS which is not restrictable by security group to a specific bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach a bucket policy to the S3 bucket that allows access only from the ALB's security group.

    Why it's wrong here

    The bucket policy would restrict access based on the source IP or VPC endpoint, but the ALB's security group is not a valid principal for S3 bucket policies. Also, the instances could still access other AWS services.

  • ✓

    Create an IAM role with a policy that grants s3:PutObject and s3:GetObject access to the specific bucket, and attach the role to the EC2 instances as an instance profile.

    Why this is correct

    An instance profile supplies temporary AWS credentials to the EC2 instance via the instance metadata service, and the attached IAM role's policy can be scoped to the exact bucket and the required actions. This provides least-privilege access, ensuring the instances can read and write only that bucket without long-lived keys or additional service permissions. Because IAM policies explicitly identify the resource (the bucket ARN) and the actions, no other AWS service or bucket is accessible unless separately allowed.

  • ✗

    Configure a VPC endpoint for S3 and modify the route table to route S3 traffic through the endpoint.

    Why it's wrong here

    A VPC endpoint for S3 (gateway or interface) enables private connectivity between the VPC and S3, but it does not limit which buckets the instances can reach; any S3 bucket accessible via the endpoint is still subject to normal IAM and bucket policies. The route table change only directs traffic destined for S3's prefix list through the endpoint, so it doesn't restrict API calls to a particular bucket. Without an accompanying IAM or bucket policy that scopes access, the instances retain whatever broad S3 permissions they previously had.

  • ✗

    Create a security group that allows outbound HTTPS traffic only to the S3 bucket's IP address range.

    Why it's wrong here

    Security groups cannot reference destination IP address ranges for S3 because S3's public IP ranges are shared with many other AWS services, making such a rule either overly permissive or ineffective. Moreover, outbound rules in a security group only filter traffic at the instance's network interface; they do not control IAM-level authorization, so the instance could still use its existing IAM credentials to call AWS APIs and access any other S3 bucket. Additionally, S3 traffic to a gateway VPC endpoint uses the prefix list rather than a specific IP, so this approach cannot be applied consistently.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.