SOA-C02 Reliability and Business Continuity Practice Question
A company wants to ensure that its S3 bucket is accessible only from a VPC. Which configuration should the SysOps Administrator implement?
⚠ Common exam trap
Candidates often think security groups can be applied to S3 buckets (Option D) because they are familiar with security groups for EC2, but S3 operates at the service level and uses bucket policies and IAM for access control, not security groups.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an S3 VPC endpoint and attach a bucket policy that restricts access to that endpoint.
An S3 VPC endpoint (either gateway or interface type) allows private connectivity between a VPC and S3 without traversing the public internet. By attaching a bucket policy that includes a condition like `aws:SourceVpce` or `aws:SourceVpc`, access is explicitly restricted to traffic originating from that specific VPC endpoint, ensuring the bucket is not accessible from any other network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an S3 VPC endpoint and attach a bucket policy that restricts access to that endpoint.
Why this is correct
Creating an S3 VPC gateway endpoint gives your VPC private, routable connectivity to S3 without traversing the public internet. To actually enforce that restriction, the bucket policy must include a condition such as "aws:SourceVpce" or "aws:SourceVpc" so that only requests originating from that endpoint or VPC are allowed; otherwise, the endpoint alone does not block other network paths. This is the only option that both enables private access and explicitly limits the source network to your VPC.
- ✗
Configure a bucket policy that allows access from the public internet.
Why it's wrong here
Writing a bucket policy that allows access from the public internet (e.g., a principal of "*" without a network condition) defeats the stated requirement to keep the bucket accessible only from the VPC. Even if requests originate from an EC2 instance inside the VPC, a broadly permissive policy also permits any external host with the bucket's endpoint to reach the objects. To restrict to the VPC, the policy must deny or conditionally allow requests based on source VPC or VPC endpoint, not merely allow all traffic.
- ✗
Make the bucket public and rely on IAM roles.
Why it's wrong here
Making the bucket public means any anonymous user on the internet can attempt to access the objects, regardless of whether IAM roles are also used. While IAM roles can provide credentials for authenticated access, a public bucket policy or public ACL allows requests without credentials, so it does not confine access to your VPC. To achieve VPC-only access, you need a bucket policy that explicitly denies requests that do not originate from the designated VPC endpoint or VPC, not just reliance on IAM identity-based controls.
- ✗
Attach a security group to the S3 bucket.
Why it's wrong here
Security groups are stateful virtual firewalls that are attached to ENIs, EC2 instances, or other supported AWS resources like RDS and Lambda; they are not a valid attachment for S3 buckets. S3 does not have the concept of a security group at the bucket level, and its network access controls are implemented via bucket policies, ACLs, IAM policies, and VPC endpoint conditions. Attempting to attach a security group to an S3 bucket is not supported, so this option cannot provide any network restriction.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.