SOA-C02 Networking and Content Delivery Practice Question
Network Topology
Refer to the exhibit. A VPC Gateway Endpoint for S3 is created and associated with route table rtb-11111111. However, an EC2 instance in a subnet that uses route table rtb-22222222 cannot access S3. What is the most likely cause?
⚠ Common exam trap
The trap is assuming that creating a VPC endpoint makes it available to the entire VPC — in reality, Gateway Endpoints must be explicitly associated with each route table, and subnets using other route tables are excluded.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The subnet's route table (rtb-22222222) does not have a route to the VPC endpoint.
A VPC Gateway Endpoint for S3 is associated with specific route tables, and only subnets using those route tables can reach S3 through the endpoint. Since the endpoint is associated with rtb-11111111 but the EC2 instance's subnet uses rtb-22222222, that subnet has no route to the endpoint and traffic cannot reach S3 via the gateway endpoint. The fix is to associate the endpoint with rtb-22222222 as well.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The VPC endpoint is not in the 'available' state.
Why it's wrong here
The VPC endpoint state is displayed as "available" in the exhibit, which means the endpoint has been fully provisioned and is ready to use. In AWS, a gateway endpoint must be in the "available" state before route tables can resolve traffic to it, so this is not the cause of the failure. Even if the state were "pending" or "failed," you would need to fix that first, but here the state is healthy.
- ✓
The subnet's route table (rtb-22222222) does not have a route to the VPC endpoint.
Why this is correct
For a gateway endpoint to carry S3 traffic from a subnet, that subnet's route table must have a route whose destination is the S3 prefix list (e.g., pl-63a5400a) and whose target is the gateway endpoint ID. The exhibit shows the endpoint is associated exclusively with rtb-11111111, whereas the subnet in question uses rtb-22222222, which has no such route. Without that route, traffic from the subnet destined to S3 follows the default route out to the internet, bypassing the endpoint entirely and therefore failing to use its private connectivity.
- ✗
The endpoint policy does not allow the s3:GetObject action.
Why it's wrong here
The VPC endpoint policy shown in the exhibit explicitly includes an Allow effect for the s3:GetObject action on the bucket ARN, so the policy is not blocking the read operation. Endpoint policies are evaluated in addition to IAM and bucket policies, but a missing Allow for GetObject would appear as an AccessDenied error, not as a network connectivity issue. Since the policy already grants the action, the real problem lies elsewhere—in the route table association.
- ✗
The VPC endpoint is in a different region from the S3 bucket.
Why it's wrong here
The VPC endpoint is located in us-east-1, which matches the region of the S3 bucket referenced in the question, so a cross-region mismatch cannot be the reason for the failure. Gateway endpoints are region-scoped and can only access buckets in the same region; if the bucket were in another region, the endpoint would not even be listed as a target for it. Because the regions align, the issue is not geographic but logical—the subnet's route table simply has no route to the endpoint.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.