S3 VPC Gateway Endpoint for Private Subnet Access
A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company wants to minimize costs and avoid NAT Gateway or NAT Instance charges. Which solution should be used?
⚠ Common exam trap
It's easy for candidates to assume a private subnet must use a NAT Gateway or NAT Instance for any internet-bound traffic, overlooking that VPC Gateway Endpoints provide free, private access to specific AWS services like S3, which can satisfy the requirement without incurring additional costs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC Gateway Endpoint for S3 and configure the instance to download patches from S3.
A VPC Gateway Endpoint for S3 allows private subnet resources to access S3 over the AWS network without traversing the internet, avoiding NAT Gateway or NAT Instance charges. The patches can be stored in an S3 bucket and downloaded by the EC2 instance using the endpoint, which uses AWS PrivateLink and does not require an internet gateway or public IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a proxy instance in a public subnet and configure the private instance to use the proxy.
Why it's wrong here
Deploying a proxy instance in a public subnet forces you to run, patch, monitor, and pay for an additional EC2 instance, and it becomes a single point of failure unless you also set up auto scaling or HA. You must configure the private instance's applications to channel traffic through the proxy, which adds operational complexity and ongoing cost. A gateway endpoint achieves the same patch-download goal without any compute cost or proxy configuration.
- ✗
Use an egress-only internet gateway for the private subnet.
Why it's wrong here
An egress-only internet gateway is designed exclusively for IPv6 traffic; it does not support IPv4. For a private IPv4 subnet there is no relevant route to it, so it cannot be used to reach S3 over IPv4. If your environment uses IPv4 resources, this option is useless and does not address outbound patch downloads.
- ✗
Attach an internet gateway to the VPC and add a route to the private subnet route table pointing to the internet gateway.
Why it's wrong here
Attaching an internet gateway to the VPC and adding a 0.0.0.0/0 route to it in the private subnet's route table eliminates the subnet's private nature because the subnet then becomes public. By definition, a private subnet is one with no route to an internet gateway; adding that route directly converts it to a public subnet and exposes the instances to the internet. Instances would also require public IPv4 addresses for the IGW to translate traffic, which is exactly what a private subnet is designed to avoid.
- ✓
Create a VPC Gateway Endpoint for S3 and configure the instance to download patches from S3.
Why this is correct
A VPC Gateway Endpoint for S3 uses the AWS-managed prefix list (com.amazonaws.<region>.s3) as a route-table target in the private subnet, so traffic to S3 stays on the AWS backbone and never leaves the VPC. Instances do not need public IPs, NAT, or an internet gateway, and gateway endpoints do not incur hourly charges. Configuring the route table and endpoint policy enables the private instance to download patches from selected S3 buckets securely without altering the instance's public/private status.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company has a VPC with a public subnet and a private subnet. They launch an EC2 instance in the private subnet with a default security group that allows all outbound traffic. The instance needs to download files from an S3 bucket in the same region. Which configuration allows this without internet access?
hard- A.Set up an AWS Direct Connect connection to the S3 bucket.
- ✓ B.Create a VPC gateway endpoint for S3 and add a route to the private subnet's route table.
- C.Attach an internet gateway to the VPC and add a route to the private subnet.
- D.Create a NAT gateway in the public subnet and add a route to the private subnet's route table.
Why B: A VPC gateway endpoint for S3 allows instances in a private subnet to access S3 without traversing the internet. By adding a route to the private subnet's route table that points to the endpoint, traffic destined for S3 stays within the AWS network. The default security group's outbound rule permits all traffic, so no additional security group changes are needed.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.