SAA-C03 Design Secure Architectures Practice Question
An EC2 instance in a private subnet must access an S3 bucket that contains regulated exports for a financial reporting platform. The security team requires access to be allowed only when traffic comes through a specific VPC endpoint. What should the architect add to the bucket policy? The design must avoid adding custom operational scripts.
⚠ Common exam trap
Candidates often confuse security group rules (which control instance-level traffic) with bucket policy conditions (which control access to the S3 service), leading them to pick Option A instead of the correct VPC endpoint condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A condition that matches aws:sourceVpce to the endpoint ID
The bucket policy can use the `aws:sourceVpce` condition key to restrict access to requests originating from a specific VPC endpoint. This ensures that only traffic routed through that endpoint can access the S3 bucket, meeting the security team's requirement without custom scripts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A security group rule that allows HTTPS to S3
Why it's wrong here
Security groups are stateful filters that attach to Elastic Network Interfaces of EC2 instances; they cannot be attached to an S3 bucket, which is a regional service with no ENI. A rule allowing HTTPS to S3 might govern outbound traffic from the instance, but it cannot validate that the traffic actually reached the S3 endpoint as intended. More importantly, it provides no way to restrict the S3 bucket to accept requests only from that specific instance, so it fails to enforce the private, endpoint-based network path.
- ✗
A condition that matches aws:RequestedRegion to the bucket Region
Why it's wrong here
The aws:RequestedRegion condition key in IAM or bucket policies restricts the AWS Region to which the API call is destined, but it has no knowledge of the network path taken. A request from a public IP to the S3 endpoint in the same Region would satisfy this condition just as easily as a request traveling through the VPC endpoint. Therefore, it cannot prove that the EC2 instance's traffic used the VPC endpoint, leaving the public internet path available and violating the 'must access via endpoint' requirement.
- ✗
A deny statement for all IAM users except the EC2 role
Why it's wrong here
A deny statement for all IAM users except the EC2 role is an identity-based restriction that limits which principals can call S3, regardless of where they are located. This does nothing to control the network route; the EC2 role's credentials could be used from any machine, and requests could still travel over the internet. It also would block legitimate access from other services like Lambda or other VPCs, whereas the requirement is specifically about network path enforcement, not principal scoping.
- ✓
A condition that matches aws:sourceVpce to the endpoint ID
Why this is correct
The aws:sourceVpce condition key in an S3 bucket policy checks the VPC endpoint ID from which the request originated. When the EC2 instance sends traffic through the designated VPC endpoint, the request includes the endpoint's ID, allowing the condition to match and granting access. Any request not coming through that endpoint, even with valid IAM credentials, would fail the condition and be denied, thus forcing the traffic to traverse the private endpoint.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.