ANS-C01 Network Implementation Practice Question
A company has a VPC with public and private subnets. The public subnet has a NAT Gateway. The private subnet instances need to access an S3 bucket in the same region. Which THREE steps should the network engineer take to ensure the most cost-effective and secure access without traversing the internet?
⚠ Common exam trap
AWS often tests the misconception that Interface Endpoints are required for all AWS services, but for S3 and DynamoDB, Gateway Endpoints are the correct, cost-effective choice, and candidates may incorrectly select Interface Endpoints due to familiarity with other services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC Gateway Endpoint for S3.
A VPC Gateway Endpoint for S3 provides private, cost-effective access to S3 without traversing the internet or requiring a NAT Gateway. It uses AWS's internal network and route table entries to direct S3 traffic through the endpoint, avoiding data transfer costs and improving security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VPC Gateway Endpoint for S3.
Why this is correct
Gateway Endpoints are free and provide private access to S3.
- ✓
Attach an endpoint policy that allows access to the specific S3 bucket.
Why this is correct
The endpoint policy controls access to S3 via the endpoint.
- ✗
Create a VPC Interface Endpoint for S3.
Why it's wrong here
Interface Endpoints for S3 are not supported in all regions and cost more.
- ✓
Update the route table for the private subnets to include a route to the S3 endpoint.
Why this is correct
Route tables must have a route to the endpoint prefix list.
- ✗
Create a NAT Gateway in the public subnet.
Why it's wrong here
NAT Gateway is not cost-effective and would route traffic over the internet.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every ANS-C01 question from scratch — 1,621 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on ANS-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a VPC with public and private subnets. They have a web server in the public subnet that needs to make API calls to Amazon S3. The web server has a public IP. What is the MOST secure way to allow the web server to access S3 without traversing the internet?
medium- ✓ A.Create a Gateway VPC Endpoint for S3 and add a route in the public subnet's route table to S3 via the endpoint
- B.Place a forward proxy server in the public subnet and configure the web server to use it for S3
- C.Create an Interface VPC Endpoint for S3 in the public subnet
- D.Set up a NAT Gateway in the same subnet and route S3 traffic through it
Why A: A Gateway VPC Endpoint for S3 allows resources within a VPC to access S3 over the AWS private network without traversing the internet. By adding a route in the public subnet's route table pointing to the endpoint, the web server can reach S3 privately, even though it has a public IP. This is the most secure option because traffic stays within the AWS backbone and does not require an internet gateway, NAT, or proxy.
Variation 2. A company has a VPC with multiple subnets. An EC2 instance in a private subnet needs to access an S3 bucket. Which AWS service should be used to allow this access without traversing the internet?
easy- A.Transit Gateway
- B.NAT gateway
- ✓ C.VPC Gateway Endpoint for S3
- D.Internet gateway
Why C: A VPC Gateway Endpoint for S3 allows EC2 instances in a private subnet to access S3 buckets without traversing the internet by using AWS's internal network. It uses prefix lists and route table entries to direct S3 traffic through the endpoint, which is horizontally scaled and highly available. This avoids the need for a NAT gateway or internet gateway, keeping traffic within the AWS backbone.
Variation 3. A company has a VPC with multiple subnets. An EC2 instance in a private subnet needs to access an S3 bucket to download files. The company wants to avoid using a NAT gateway and minimize latency. Which solution should be used?
hard- ✓ A.Create a VPC endpoint for S3 and attach it to the private subnet's route table.
- B.Place the instance in a public subnet and use a NAT gateway.
- C.Use a VPC endpoint for EC2.
- D.Use an internet gateway and a route to 0.0.0.0/0.
Why A: A VPC endpoint for S3 allows the EC2 instance in the private subnet to access S3 directly over the AWS network, avoiding internet-bound traffic and eliminating the need for a NAT gateway. This minimizes latency because traffic stays within the AWS backbone and does not traverse the public internet. Attaching the endpoint to the private subnet's route table ensures that S3-bound traffic is routed through the endpoint.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.