A company has an S3 bucket with a bucket policy that grants access to an IAM role. The security team wants to restrict access to only requests that originate from the company's VPC. How can this be achieved?
Adding a bucket policy condition with the aws:SourceVpce key set to the specific VPC endpoint ID is the correct approach because this condition is automatically populated when a request reaches S3 through that exact endpoint. This ensures that only requests that travel via the designated VPC endpoint are allowed, effectively bounding access to instances in the associated VPC. It is a recommended, unambiguous way to enforce network-level restrictions on S3 resources and works in tandem with IAM policies that grant permissions.
Why this answer
To restrict S3 bucket access to requests originating from a VPC, you add a condition to the bucket policy using the aws:SourceVpce condition key with the VPC endpoint ID. This ensures that only requests traversing the specified VPC endpoint (and thus originating from within the VPC) are allowed, which is the standard, secure way to enforce VPC-origin access for S3.
Exam trap
The trap is confusing IAM policy condition keys with bucket policy condition keys — candidates often pick aws:SourceVpce in an IAM role policy, but the exam expects you to know it must be in the bucket policy to enforce VPC endpoint origin.
How to eliminate wrong answers
Option A is wrong because creating an IAM role assumable only by VPC instances does not restrict S3 access to VPC-originated requests — the role could still be used from outside the VPC if credentials leak, and it doesn't enforce network origin. Option B is wrong because aws:SourceVpce is a bucket-policy condition key, not an IAM role policy condition key; using it in an IAM role policy will not enforce VPC endpoint origin for S3 access. Option C is wrong because aws:SourceIp with the VPC CIDR range is unreliable — it can be spoofed or bypassed via NAT/proxy, and it doesn't guarantee the request came through the VPC endpoint; it also fails for private IP ranges that aren't routable on the public internet.