Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A security engineer is troubleshooting connectivity issues from an EC2 instance in a private subnet to an S3 bucket. The instance has a security group allowing outbound HTTPS (443) to 0.0.0.0/0, and the subnet's network ACL allows outbound HTTPS to 0.0.0.0/0. However, requests to S3 are timing out. Which additional configuration is most likely required?

⚠ Common exam trap

The trap is assuming that a permissive security group and NACL are sufficient for outbound connectivity — candidates forget that a private subnet has no route to the internet and that S3 access requires either a NAT gateway or a VPC Gateway Endpoint.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a VPC Gateway Endpoint for S3 and update the route table

An EC2 instance in a private subnet has no route to the internet, so it cannot reach S3's public endpoints even though the security group and NACL allow outbound HTTPS. The correct fix is to create a VPC Gateway Endpoint for S3 and add a route in the subnet's route table pointing S3 traffic to the endpoint. This keeps traffic on the AWS private network and avoids the need for a NAT gateway.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM role to the EC2 instance with S3 permissions

    Why it's wrong here

    Attaching an IAM role with S3 permissions addresses authentication and authorization at the AWS API layer, but the instance cannot even establish a TCP connection to S3 because no route exists in the private subnet. S3 requests from an unauthorized principal would fail with Access Denied errors, whereas connectivity issues manifest as connection timeouts or 'Unable to connect' errors, clearly indicating the problem occurs before IAM evaluation. Therefore, an IAM role alone cannot fix the routing failure described.

  • ✗

    Modify the security group to allow traffic to the S3 region-specific IP range

    Why it's wrong here

    Modifying the security group to allow S3 regional IP ranges is ineffective here because the security group already permits all outbound HTTPS, so traffic is not being blocked by security-group rules. The connectivity failure stems from the private subnet's route table lacking a route to S3 destinations; without a gateway endpoint or NAT, those IP ranges are unreachable regardless of security-group authorization. Additionally, when using a VPC Gateway Endpoint, traffic is examined against the endpoint's prefix list, not arbitrary regional IP CIDRs.

  • ✓

    Add a VPC Gateway Endpoint for S3 and update the route table

    Why this is correct

    A VPC Gateway Endpoint for S3 is the correct fix because it installs a route entry in the private subnet's route table using the S3 prefix list, allowing traffic destined for S3 to traverse AWS's internal network instead of requiring an internet gateway or NAT device. Without this endpoint, an instance in a private subnet has no viable next hop for S3 public IP ranges, so TCP connections time out. Updating the route table to include the endpoint's prefix-list destination completes the configuration.

  • ✗

    Configure a TLS termination proxy

    Why it's wrong here

    A TLS termination proxy is used at the application layer to decrypt inbound TLS and pass plaintext to backend services; S3 natively terminates TLS on its HTTPS endpoints, so adding another proxy provides no benefit for outbound S3 API calls. Moreover, even if the proxy were configured as an outbound forward proxy, it would itself need a route to S3—either through a NAT gateway, internet gateway, or a VPC endpoint—so it does not eliminate the underlying private-subnet routing problem.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.