Attach a resource policy to the API Gateway API allowing only the specific VPC IDs
A company has deployed a new REST API by using Amazon API Gateway. The company uses the API to access confidential data. The API must be accessed from only specific VPCs in the company. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
API Gateway has no security groups, ACLs, or attachable IAM roles, which eliminates options B, C, and D at their premise (A). The only mechanism API Gateway exposes for caller-based restriction is its resource policy, and the aws:SourceVpc condition is what allows it to permit only specified VPC IDs (A). Srikantha and Ky_24 both described this, noting that resource policies can restrict access based on specific conditions such as VPC IDs.
The API must be reachable only from specific VPCs in the company, which is a caller-identity restriction rather than a network configuration. Amazon API Gateway supports a resource policy on the API, and that policy can be scoped with the aws:SourceVpc or aws:SourceVpce condition so that requests are accepted only when they originate through the specified VPCs or VPC endpoints, with the source VPC also usable as a source for an IAM deny statement. Attaching such a resource policy restricts API access to the named VPCs and nothing else.
Adding a security group to the API Gateway API with inbound rules limited to the VPC IP ranges (B) — API Gateway is a managed service fronted by AWS-owned infrastructure and has no security groups associated with it, so nothing can be attached. Creating an IAM role and attaching it to the API Gateway API (C) — API Gateway does not accept an IAM role in the way the option implies, and an identity-based role on its own would not express a source VPC restriction; the control belongs in a resource policy. Adding an ACL with outbound rules (D) — API Gateway has no ACLs, and outbound rules would not restrict inbound callers in any case, since the requirement is about who may call the API.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The requirement is that the API be accessible only from specific VPCs, which is a restriction on the caller's origin. Amazon API Gateway supports a resource policy attached to the API, and that policy can use the aws:SourceVpc or aws:SourceVpce condition to permit requests only when they originate from the specified VPCs or VPC endpoints, with the source VPC also usable in a Deny statement for callers outside the set (A). Srikantha noted that API Gateway supports resource policies allowing control of who can access the API based on source IP address, VPC ID, or specific IP ranges, which is exactly the required capability, and Ky_24 explained the same in terms of restricting access with specific conditions such as VPC IDs. CHRIS12722222 cited the AWS documentation on creating a private API for the same mechanism. A is the correct answer.Why the Other Options Are Wrong
B adds a security group to the API Gateway API and configures inbound rules to allow only the specific VPC IP address ranges. API Gateway is a managed service whose endpoints are fronted by AWS-owned infrastructure, and it has no security groups that can be associated with an API, so there is nothing for this rule to attach to. C creates an IAM role and attaches it to the API Gateway API, configuring it to allow only the specific VPC IDs. API Gateway does not take an attached IAM role as an access-control mechanism in the way described, and an identity-based role alone would not express a source VPC restriction; the mechanism for that is a resource policy with a source VPC condition. D adds an ACL to the API Gateway API and configures outbound rules to allow only the specific VPC IP ranges. API Gateway has no ACLs, and outbound rules would not restrict which callers may invoke the API in any case, since the requirement concerns inbound callers. A is correct.Community Comment Notes
Community voted A unanimously. Srikantha explained that API Gateway supports resource policies that allow control of who can access the API based on source IP address, VPC ID, or specific IP ranges, and that this restricts access to the specified VPCs. Ky_24 restated the same reasoning about restricting access with specific conditions such as VPC IDs. CHRIS12722222 cited the AWS documentation page for creating a private API. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →