SOA-C02 Security and Compliance Practice Question
A company has an EC2 instance that needs to access an S3 bucket. The instance is launched in a private subnet with no internet gateway. What is the most secure way to provide access to S3 without traversing the internet?
⚠ Common exam trap
A common mix-up: candidates confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for private subnet outbound traffic, forgetting that S3 can be accessed directly via a gateway endpoint without internet routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an S3 VPC gateway endpoint
An S3 VPC gateway endpoint allows EC2 instances in a private subnet to access S3 privately using AWS’s internal network, without requiring an internet gateway, NAT gateway, or public IP. Traffic stays within the AWS backbone, never traversing the internet, which provides the most secure and cost-effective solution for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a NAT gateway in a public subnet
Why it's wrong here
A NAT gateway is designed for outbound-only internet connectivity from private subnets, but it still routes S3 traffic through the public internet using the gateway's Elastic IP and its own route. That means the connection is neither private nor free from internet dependencies, and it does not establish a secure perimeter around S3 access. It also incurs hourly charges and per-GB data processing costs, making it an inferior choice to a VPC endpoint.
- ✓
Create an S3 VPC gateway endpoint
Why this is correct
An S3 VPC gateway endpoint is a component you add to the VPC's route table that directs S3-bound traffic to the AWS network via a prefix list, completely bypassing the internet. Because it works via the AWS internal backbone, instances in private subnets can reach S3 without a NAT gateway, internet gateway, public IP, or VPN, and there is no charge for the gateway endpoint itself. The route is confined to the customer VPC and AWS's shared network, making it a private and secure method for S3 access.
- ✗
Set up an AWS Direct Connect connection
Why it's wrong here
Direct Connect is a physical dedicated line from your on-premises data center to an AWS Direct Connect location; it is not a VPC component that steers instance-to-S3 traffic. Even after establishing Direct Connect, you must pair it with either a public virtual interface that uses S3's public endpoints or a VPC endpoint to get private connectivity — the Direct Connect link alone does not imply S3 is reached privately. For an EC2 instance already inside the VPC, adding Direct Connect is irrelevant, expensive, and does not meet the stated requirement.
- ✗
Attach an internet gateway to the VPC and a public IP to the instance
Why it's wrong here
This approach relies on an internet gateway and a public IPv4 address to expose the instance to the public internet, and any S3 traffic is transmitted over the internet rather than the AWS private network. It increases the attack surface because the instance is openly addressable from the internet, demanding careful security-group rules, and it still incurs data transfer costs for internet egress. A VPC endpoint avoids these exposure and cost issues while keeping the instance off the public internet.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.