AWS Certified Developer – Associate (DVA-C02)SecurityHard

A developer is building a new application that needs to access an Amazon S3 bucket. The security team has mandated that access to the S3 bucket must be restricted to specific IAM roles and that all data transfers to and from S3 must occur over private AWS networks, without traversing the public internet. Which two configurations are required to meet these security requirements?

  1. AConfigure an S3 bucket policy and enable S3 Transfer Acceleration.
  2. BConfigure an S3 bucket policy and create a Gateway VPC Endpoint for S3.
  3. CConfigure an IAM role for the application and use S3 Cross-Region Replication.
  4. DConfigure an S3 Access Point and enable S3 Object Lock.
Show answer & explanation

Correct answer: B. Configure an S3 bucket policy and create a Gateway VPC Endpoint for S3.

An S3 bucket policy is used to restrict access to specific IAM roles, ensuring authorization. A Gateway VPC Endpoint for S3 allows EC2 instances within a VPC to access S3 over the AWS private network, preventing data from traversing the public internet.

Why the other options are wrong

  • A. S3 Transfer Acceleration speeds up transfers over the internet, which contradicts the requirement to avoid the public internet.
  • C. Cross-Region Replication is for data redundancy, not for controlling access or private network access paths.
  • D. S3 Access Points simplify access management for complex S3 data access, and Object Lock provides immutability, neither directly addresses private network access or restricting to specific IAM roles.

S3 Access Control & Private Access

S3 bucket policies control access permissions, while S3 Gateway VPC Endpoints provide private, secure access to S3 from within a VPC, avoiding the public internet.

  • Bucket policies define who can access S3 resources and what actions they can perform.
  • Gateway VPC Endpoints route S3 traffic over AWS's private network.
  • Endpoints are free of charge.

Memory trick: Bucket policies guard the gate, Gateway Endpoints keep it private.

More Security questions