A global enterprise needs to store highly sensitive customer data in an Amazon S3 bucket. Access to this data must be strictly controlled, allowing only specific IAM roles from a particular AWS account to read objects. Furthermore, the data must only be accessible from within the company's Virtual Private Cloud (VPC) through a private network connection, never over the public internet. Which combination of S3 bucket policies and network configurations will enforce these requirements?
- AConfigure the S3 bucket policy to allow access only for the specific IAM roles, and use a VPC endpoint for S3.
- BConfigure the S3 bucket policy to deny access if the source IP is not from the VPC endpoint, and attach an S3 VPC endpoint policy to restrict access to the specific IAM roles.
- CConfigure the S3 bucket policy to allow access for the specific IAM roles and include a 'aws:SourceVpce' condition, and use a VPC endpoint for S3.
- DConfigure the S3 bucket policy to allow access only for the specific IAM roles from the specified AWS account, and configure a security group on the S3 VPC endpoint to restrict outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure the S3 bucket policy to allow access for the specific IAM roles and include a 'aws:SourceVpce' condition, and use a VPC endpoint for S3.
Using a VPC endpoint for S3 ensures private connectivity. The S3 bucket policy with a 'aws:SourceVpce' condition explicitly restricts access to requests originating from the specified VPC endpoint, satisfying the private network access requirement. Combining this with IAM role restrictions enforces granular access control.
Why the other options are wrong
- A. While a VPC endpoint provides private connectivity, the bucket policy needs an explicit condition (like `aws:SourceVpce`) to *enforce* that access *must* come through that specific endpoint, preventing public internet access.
- B. Denying access if the source IP is not from the VPC endpoint is a valid approach, but the `aws:SourceVpce` condition is more direct and robust for ensuring access *through* the endpoint. The VPC endpoint policy also restricts access, but the bucket policy is the ultimate gatekeeper.
- D. Security groups on the VPC endpoint control *outbound* traffic from the VPC to S3, but they don't inherently prevent S3 from being accessed *over the public internet* if the bucket policy allows it. The bucket policy needs to explicitly deny public access or enforce VPC endpoint usage.
S3 VPC Endpoint with Bucket Policy
Combining an Amazon S3 VPC endpoint with a bucket policy containing the `aws:SourceVpce` condition to ensure S3 access is restricted to specific IAM roles and only originates from within a specified VPC, never over the public internet.
- VPC endpoints provide private connectivity to S3.
- `aws:SourceVpce` condition in a bucket policy restricts access to specific VPC endpoints.
- Bucket policies enforce access control at the S3 bucket level.
- Ensures data never traverses the public internet.
Memory trick: VPC Endpoint + SourceVpce locks S3.