SCS-C02 Infrastructure Security Practice Question
A company wants to restrict access to an S3 bucket so that only traffic from a specific VPC can download objects. Which combination of actions should the company take? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an S3 bucket policy that allows access only from the VPC using the aws:SourceVpc condition.
To restrict access to an S3 bucket so that only traffic from a specific VPC can download objects, the correct combination is to create an S3 bucket policy that uses the aws:SourceVpc condition (Option C) and create a VPC endpoint for Amazon S3 in the VPC (Option E). The bucket policy with aws:SourceVpc ensures that only requests originating from the specified VPC are allowed, while the VPC endpoint enables private connectivity between the VPC and S3 without traversing the internet. Option A (Internet gateway) would make the VPC publicly accessible and is not required for private access. Option B (NAT gateway) is used for outbound internet access from private subnets, not for restricting access to S3. Option D (security group) cannot be attached to an S3 bucket; security groups apply to EC2 instances or other resources, not to S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an Internet gateway to the VPC and route traffic through it.
Why it's wrong here
Attaching an Internet gateway and updating route tables gives instances a public path to the internet, but it does not create any S3-specific access control. Any bucket policy or IAM permission still governs access, and because traffic egresses through the IGW it goes to S3's public endpoints rather than through a private VPC endpoint. This arrangement widens, rather than restricts, the network paths that can reach S3.
- ✗
Attach a security group to the S3 bucket.
Why it's wrong here
Security groups are stateful, instance-level or ENI-level firewalls, not resources that can be attached to an S3 bucket. S3 is a managed service with no network interface in the customer VPC, so a security group cannot filter requests to it. Access decisions for S3 are made via bucket policies, IAM policies, and S3 access points, not security groups.
- ✓
Create an S3 bucket policy that allows access only from the VPC using the aws:SourceVpc condition.
Why this is correct
Create a bucket policy whose Principal is the intended IAM role or account and add a Condition using the aws:SourceVpc key set to the VPC ID. This allows requests only when they originate from that exact VPC, so traffic from any other VPC or the public internet is blocked. To make this work, requests must arrive through a VPC endpoint for S3, because the aws:SourceVpc condition key is populated only for traffic that uses an endpoint.
- ✗
Create a NAT gateway in the VPC for outbound traffic.
Why it's wrong here
A NAT gateway allows instances in private subnets to initiate outbound connections to the internet, but it is an outbound connectivity mechanism, not an access-control boundary for S3. Traffic to S3 through a NAT gateway traverses the public S3 endpoint, so it does not establish any private or restricted network path. It also does not prevent other VPCs or on-premises users from reaching the bucket if the bucket policy permits it.
- ✓
Create a VPC endpoint for Amazon S3 in the VPC.
Why this is correct
Creating a gateway endpoint for S3 makes S3 reachable from the VPC through AWS's private network without using the public internet. This is a necessary component of a 'VPC-only' architecture because it lets the S3 bucket policy's aws:SourceVpc condition be evaluated. By itself the endpoint does not revoke public access; you still need the bucket policy to deny requests that do not come from the VPC, so the endpoint is correct only when paired with the appropriate resource policy.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.