Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

A company wants to ensure that its S3 bucket is accessible only from a VPC. Which configuration should the SysOps Administrator implement?

⚠ Common exam trap

Candidates often think security groups can be applied to S3 buckets (Option D) because they are familiar with security groups for EC2, but S3 operates at the service level and uses bucket policies and IAM for access control, not security groups.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an S3 VPC endpoint and attach a bucket policy that restricts access to that endpoint.

An S3 VPC endpoint (either gateway or interface type) allows private connectivity between a VPC and S3 without traversing the public internet. By attaching a bucket policy that includes a condition like `aws:SourceVpce` or `aws:SourceVpc`, access is explicitly restricted to traffic originating from that specific VPC endpoint, ensuring the bucket is not accessible from any other network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an S3 VPC endpoint and attach a bucket policy that restricts access to that endpoint.

    Why this is correct

    Creating an S3 VPC gateway endpoint gives your VPC private, routable connectivity to S3 without traversing the public internet. To actually enforce that restriction, the bucket policy must include a condition such as "aws:SourceVpce" or "aws:SourceVpc" so that only requests originating from that endpoint or VPC are allowed; otherwise, the endpoint alone does not block other network paths. This is the only option that both enables private access and explicitly limits the source network to your VPC.

  • ✗

    Configure a bucket policy that allows access from the public internet.

    Why it's wrong here

    Writing a bucket policy that allows access from the public internet (e.g., a principal of "*" without a network condition) defeats the stated requirement to keep the bucket accessible only from the VPC. Even if requests originate from an EC2 instance inside the VPC, a broadly permissive policy also permits any external host with the bucket's endpoint to reach the objects. To restrict to the VPC, the policy must deny or conditionally allow requests based on source VPC or VPC endpoint, not merely allow all traffic.

  • ✗

    Make the bucket public and rely on IAM roles.

    Why it's wrong here

    Making the bucket public means any anonymous user on the internet can attempt to access the objects, regardless of whether IAM roles are also used. While IAM roles can provide credentials for authenticated access, a public bucket policy or public ACL allows requests without credentials, so it does not confine access to your VPC. To achieve VPC-only access, you need a bucket policy that explicitly denies requests that do not originate from the designated VPC endpoint or VPC, not just reliance on IAM identity-based controls.

  • ✗

    Attach a security group to the S3 bucket.

    Why it's wrong here

    Security groups are stateful virtual firewalls that are attached to ENIs, EC2 instances, or other supported AWS resources like RDS and Lambda; they are not a valid attachment for S3 buckets. S3 does not have the concept of a security group at the bucket level, and its network access controls are implemented via bucket policies, ACLs, IAM policies, and VPC endpoint conditions. Attempting to attach a security group to an S3 bucket is not supported, so this option cannot provide any network restriction.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.