DOP-C02 Incident and Event Response Practice Question
An application running on an EC2 instance in a private subnet needs to access an S3 bucket. The instance has an IAM role with S3 access. However, the application is failing with timeout errors. The security group allows all outbound traffic, and the NACL allows outbound ephemeral ports. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No VPC endpoint for S3
A VPC endpoint for S3 (Gateway or Interface) is needed for private subnet access to S3 without NAT. Without a VPC endpoint, the EC2 instance in a private subnet cannot reach S3, resulting in timeout errors. The security group and NACL settings are permissive, so they are not the issue. Option B is incorrect because the instance is in a private subnet; routing to an Internet Gateway is not necessary and would require a NAT device. Option C is incorrect because the IAM role has the necessary S3 permissions. Option D is incorrect because no HTTP proxy is required for S3 access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No VPC endpoint for S3
Why this is correct
An EC2 instance in a private subnet has no route to the public internet unless a NAT device or VPC endpoint is provisioned. Since no VPC endpoint for S3 is listed as existing, traffic from the instance to S3 cannot traverse the AWS backbone via the private subnet. A gateway endpoint or interface endpoint for S3 is required to establish private connectivity without leaving the AWS network, making the absent endpoint the root cause of the failure.
- ✗
Missing route in the route table to an Internet Gateway
Why it's wrong here
Private subnets are deliberately configured without a route to an Internet Gateway, so the absence of such a route is expected and not an error. The correct path for S3 access from a private subnet is either through a NAT gateway (which itself requires an IGW in a public subnet) or through a VPC endpoint, not through a direct IGW route. Therefore, the missing IGW route is not the cause because it is not a valid design pattern for private-subnet resources to route directly to S3.
- ✗
IAM role does not have correct trust policy
Why it's wrong here
An IAM role's trust policy determines which entities are allowed to assume that role, not whether the instance can reach S3 over the network. The instance already has an instance profile, and if the role includes S3 permissions, trust policy is not the blocker; the failure is at the network layer. Trust policy misconfiguration would typically manifest as an authorization error when attempting to call the role's credentials, not as a connectivity timeout or endpoint unreachable error.
- ✗
Missing HTTP proxy configuration
Why it's wrong here
An HTTP proxy is an optional intermediary that can be used to control or inspect outbound web traffic, but it is not a prerequisite for S3 communication. If a proxy were required, it would normally be configured on the instance's environment variables or software settings, and the question does not indicate one exists or is needed. Since VPC endpoints use PrivateLink over the AWS network, they do not depend on HTTP proxy configuration, so the missing proxy is not the reason for the S3 access failure.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.