Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to allow an EC2 instance to access an S3 bucket without exposing the instance to the internet. Which AWS service should be used to achieve this?

⚠ Common exam trap

Many candidates confuse Gateway Endpoints with Interface Endpoints (powered by AWS PrivateLink) and incorrectly assume a NAT Gateway is required for private subnet access, but Gateway Endpoints are specifically designed for S3 and DynamoDB and do not require any additional infrastructure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Endpoint (Gateway type) for S3

A VPC Endpoint (Gateway type) for S3 allows EC2 instances within a VPC to access S3 buckets privately using AWS's internal network, without traversing the internet. This is achieved by adding an endpoint route in the VPC route table that directs S3 traffic to the endpoint, which uses AWS's private infrastructure. It eliminates the need for an internet gateway, NAT gateway, or VPN connection, ensuring the instance remains isolated from the public internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NAT Gateway

    Why it's wrong here

    A NAT Gateway is a managed service that enables instances in a private subnet to initiate outbound IPv4 traffic to the internet and receive corresponding return traffic. It does not create a private path to S3; traffic destined for S3 through a NAT Gateway would still egress via an Internet Gateway and traverse the public internet, incurring NAT data processing charges and requiring public IP addresses for S3 access. This violates the requirement for private connectivity and adds unnecessary cost and latency.

  • ✗

    AWS Site-to-Site VPN

    Why it's wrong here

    An AWS Site-to-Site VPN creates an encrypted IPsec tunnel between an on-premises router and a virtual private gateway or transit gateway in the VPC, typically used to connect corporate networks to AWS. It is not relevant for EC2-to-S3 communication because both resources are already inside AWS; even if routing were manipulated to send S3 traffic through the VPN, it would hairpin out to on-premises and back, adding significant latency and egress costs while still terminating at S3's public endpoint.

  • ✗

    Internet Gateway

    Why it's wrong here

    An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that enables communication between a VPC and the public internet. Attaching an IGW to the VPC and adding routes would allow EC2 instances with public IP addresses to reach S3 over the public endpoint, but it does not provide private connectivity and introduces exposure to the public internet, making it unsuitable for a private, secure access pattern. An IGW by itself also cannot support instances that lack public IPs.

  • ✓

    VPC Endpoint (Gateway type) for S3

    Why this is correct

    A gateway VPC endpoint for S3 is the correct solution because it provides private connectivity from the VPC to S3 without requiring an Internet Gateway, NAT Gateway, or public IP address. It is implemented as a route-table entry using a prefix list for S3, directing traffic to the S3 service over the AWS private network. This endpoint does not incur per-hour or data-processing charges, and it keeps traffic entirely within AWS, satisfying both security and cost-efficiency requirements.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.