SCS-C02 Infrastructure Security Practice Question
A company has a VPC with a public subnet and a private subnet. They launch an EC2 instance in the private subnet with a default security group that allows all outbound traffic. The instance needs to download files from an S3 bucket in the same region. Which configuration allows this without internet access?
⚠ Common exam trap
Candidates often confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for any outbound traffic, missing that S3 and DynamoDB support gateway endpoints which work directly from private subnets without internet access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VPC gateway endpoint for S3 and add a route to the private subnet's route table.
A VPC gateway endpoint for S3 allows instances in a private subnet to access S3 without traversing the internet. By adding a route to the private subnet's route table that points to the endpoint, traffic destined for S3 stays within the AWS network. The default security group's outbound rule permits all traffic, so no additional security group changes are needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up an AWS Direct Connect connection to the S3 bucket.
Why it's wrong here
AWS Direct Connect establishes a dedicated network connection from an on-premises data center to AWS, not a private path for VPC instances to reach S3. Even with a public VIF, traffic from a private subnet would still need to route through the VPC and out to the internet, and no route or endpoint is defined. This option is irrelevant to the internal routing needs of the VPC and does not satisfy the requirement for private S3 access.
- ✓
Create a VPC gateway endpoint for S3 and add a route to the private subnet's route table.
Why this is correct
A VPC gateway endpoint for S3 is a horizontally scaled, highly available service that allows instances in a private subnet to communicate with S3 without traversing the internet or requiring public IP addresses. Adding a route in the private subnet's route table that points the S3 prefix list (e.g., com.amazonaws.region.s3) to the endpoint ID (pl-xxxx) keeps all traffic within the AWS network, ensuring low latency and enhanced security. This is the recommended, cost-effective approach because the gateway endpoint itself is free and there are no data transfer charges for S3 traffic.
- ✗
Attach an internet gateway to the VPC and add a route to the private subnet.
Why it's wrong here
Attaching an internet gateway (IGW) to the VPC and adding a route to the private subnet would make that subnet effectively public, as the route would direct all traffic to the IGW. This exposes instances to potential inbound internet traffic and forces S3 traffic to travel over the public internet, defeating the need for private connectivity. An IGW is designed for internet access, not for secure, private service access, and would not keep S3 traffic within AWS's internal network.
- ✗
Create a NAT gateway in the public subnet and add a route to the private subnet's route table.
Why it's wrong here
A NAT gateway in the public subnet provides outbound internet connectivity to instances in a private subnet, but it routes S3 traffic through the public internet to S3's public endpoints, which is not private and incurs data transfer charges. Additionally, NAT gateways are managed services with an hourly cost and per-gigabyte processing fees, making them more expensive than a gateway endpoint. For private S3 access, a VPC gateway endpoint is the appropriate solution because it bypasses the internet entirely and eliminates the need for a NAT gateway.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.