AWS Certified Security – SpecialtyDomain 5: Data ProtectionHard

A global enterprise needs to store highly sensitive customer data in an Amazon S3 bucket. Access to this S3 bucket must be restricted to resources originating only from a specific Amazon Virtual Private Cloud (VPC) within the same AWS Region. Furthermore, all data transfers between the VPC and S3 must remain within the AWS network and not traverse the public internet. Which solution effectively enforces these access and network requirements?

  1. AUse an S3 Interface VPC Endpoint, and configure Security Groups and Network ACLs to control access.
  2. BSet up an S3 Gateway VPC Endpoint and configure an S3 bucket policy to restrict access to the VPC Endpoint.
  3. CEnable S3 Block Public Access settings at the account level and use IAM roles for S3 access.
  4. DConfigure an S3 bucket policy to allow access only from specific IP addresses of EC2 instances within the VPC.
Show answer & explanation

Correct answer: B. Set up an S3 Gateway VPC Endpoint and configure an S3 bucket policy to restrict access to the VPC Endpoint.

An S3 Gateway VPC Endpoint allows private connectivity to S3 from within a VPC without traversing the public internet. Coupled with an S3 bucket policy that explicitly allows access only through this VPC endpoint, it enforces both the private network path and VPC-specific access restrictions.

Why the other options are wrong

  • A. An S3 Interface VPC Endpoint (powered by AWS PrivateLink) is for accessing S3 from *on-premises* or *other VPCs* over PrivateLink. While it offers private connectivity, a Gateway endpoint is the standard and more cost-effective solution for S3 access *from within the same VPC*.
  • C. S3 Block Public Access prevents public access to buckets, but it doesn't restrict access to a *specific VPC* or ensure traffic stays off the public internet for authorized users.
  • D. Restricting by IP addresses of EC2 instances is not scalable, and these IPs can change. More importantly, it doesn't guarantee that traffic stays within the AWS network; it could still traverse the public internet.

S3 Gateway VPC Endpoint with Bucket Policy

An S3 Gateway VPC Endpoint enables private connectivity from a VPC to Amazon S3, preventing traffic from traversing the public internet. An S3 bucket policy can then restrict access to only requests originating from this specific VPC endpoint.

  • Provides a reliable and secure connection to S3 from a VPC.
  • Traffic remains entirely within the AWS network.
  • Bucket policies use the `aws:SourceVpce` condition key to enforce access via the endpoint.

Memory trick: Gateway Guards S3, Guiding Good VPC Traffic.

More Domain 5: Data Protection questions