ANS-C01 Network Implementation Practice Question
Network Topology
A network engineer runs the above command to list VPC endpoints. The engineer notices that the second endpoint (vpce-0b2c3d4e5f6g7h8i9) does not have a policy document displayed. What does this indicate?
⚠ Common exam trap
A common mix-up: candidates assume a missing policy document means the endpoint has no policy or is broken, when in fact AWS omits the default full-access policy from the CLI output, leading to confusion with inactive endpoints or service-specific limitations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The endpoint has the default full-access policy.
When a VPC endpoint is created without a custom policy document, AWS automatically applies a default full-access policy that allows all principals to perform all actions on all resources through the endpoint. The AWS CLI command `describe-vpc-endpoints` omits the policy field when the default policy is in effect, because the default policy is not stored as a separate document; it is an implicit behavior of the endpoint. Therefore, the absence of a policy document in the output indicates the endpoint is using the default full-access policy, making option D correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The endpoint is configured to use an AWS managed policy that is not shown.
Why it's wrong here
AWS does not use managed policies for VPC endpoints; the policy is either custom or default.
- ✗
The endpoint is not active and needs to be recreated.
Why it's wrong here
The endpoint is listed, so it is active.
- ✗
The endpoint is for DynamoDB, which does not support endpoint policies.
Why it's wrong here
DynamoDB endpoints support policies; the default is full access.
- ✓
The endpoint has the default full-access policy.
Why this is correct
If no custom policy is specified, the default policy allows full access.
Go deeper
Related to this question
About these practice questions
This ANS-C01 question is part of Courseiva's 1,621-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ANS-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ANS-C01 exam.