ANS-C01 Network Management and Operations Practice Question
A company has a VPC with public and private subnets. The public subnet has a NAT Gateway, and the private subnet has EC2 instances that need internet access. The private instances can reach the internet, but cannot access an S3 bucket in the same region using the S3 gateway endpoint. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The private subnet's route table does not have a route to the S3 gateway endpoint.
For private instances to use a gateway endpoint, the route table for the private subnet must have a route pointing to the S3 endpoint. Additionally, the endpoint's policy must allow the traffic. The NAT Gateway is not used for gateway endpoints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The S3 gateway endpoint is not in the same VPC.
Why it's wrong here
The endpoint is created in the same VPC, but the route is missing.
- ✗
The S3 bucket policy does not allow access from the VPC.
Why it's wrong here
Bucket policy is for cross-account or specific conditions; the gateway endpoint policy is the primary control.
- ✗
The NAT Gateway is in a different availability zone than the private instances.
Why it's wrong here
NAT Gateway is used for internet access; S3 gateway endpoint does not use NAT.
- ✓
The private subnet's route table does not have a route to the S3 gateway endpoint.
Why this is correct
Without a route to the endpoint, traffic to S3 goes through the NAT Gateway or is dropped.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.