Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Network Topology
$ aws ec2 describe-vpc-endpointsregion us-east-1Refer to the exhibit.```"VpcEndpoints": ["VpcEndpointId": "vpce-0a1b2c3d4e5f6g7h8","VpcId": "vpc-12345678","ServiceName": "com.amazonaws.us-east-1.s3","VpcEndpointType": "Gateway","RouteTableIds": ["rtb-11111111"],"PolicyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":\"*\",\"Action\":\"s3:GetObject\",\"Resource\":\"*\"}]}","State": "available"

Refer to the exhibit. A VPC Gateway Endpoint for S3 is created and associated with route table rtb-11111111. However, an EC2 instance in a subnet that uses route table rtb-22222222 cannot access S3. What is the most likely cause?

⚠ Common exam trap

The trap is assuming that creating a VPC endpoint makes it available to the entire VPC — in reality, Gateway Endpoints must be explicitly associated with each route table, and subnets using other route tables are excluded.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The subnet's route table (rtb-22222222) does not have a route to the VPC endpoint.

A VPC Gateway Endpoint for S3 is associated with specific route tables, and only subnets using those route tables can reach S3 through the endpoint. Since the endpoint is associated with rtb-11111111 but the EC2 instance's subnet uses rtb-22222222, that subnet has no route to the endpoint and traffic cannot reach S3 via the gateway endpoint. The fix is to associate the endpoint with rtb-22222222 as well.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPC endpoint is not in the 'available' state.

    Why it's wrong here

    The VPC endpoint state is displayed as "available" in the exhibit, which means the endpoint has been fully provisioned and is ready to use. In AWS, a gateway endpoint must be in the "available" state before route tables can resolve traffic to it, so this is not the cause of the failure. Even if the state were "pending" or "failed," you would need to fix that first, but here the state is healthy.

  • ✓

    The subnet's route table (rtb-22222222) does not have a route to the VPC endpoint.

    Why this is correct

    For a gateway endpoint to carry S3 traffic from a subnet, that subnet's route table must have a route whose destination is the S3 prefix list (e.g., pl-63a5400a) and whose target is the gateway endpoint ID. The exhibit shows the endpoint is associated exclusively with rtb-11111111, whereas the subnet in question uses rtb-22222222, which has no such route. Without that route, traffic from the subnet destined to S3 follows the default route out to the internet, bypassing the endpoint entirely and therefore failing to use its private connectivity.

  • ✗

    The endpoint policy does not allow the s3:GetObject action.

    Why it's wrong here

    The VPC endpoint policy shown in the exhibit explicitly includes an Allow effect for the s3:GetObject action on the bucket ARN, so the policy is not blocking the read operation. Endpoint policies are evaluated in addition to IAM and bucket policies, but a missing Allow for GetObject would appear as an AccessDenied error, not as a network connectivity issue. Since the policy already grants the action, the real problem lies elsewhere—in the route table association.

  • ✗

    The VPC endpoint is in a different region from the S3 bucket.

    Why it's wrong here

    The VPC endpoint is located in us-east-1, which matches the region of the S3 bucket referenced in the question, so a cross-region mismatch cannot be the reason for the failure. Gateway endpoints are region-scoped and can only access buckets in the same region; if the bucket were in another region, the endpoint would not even be listed as a target for it. Because the regions align, the issue is not geographic but logical—the subnet's route table simply has no route to the endpoint.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.