Attach a resource policy to the API Gateway API allowing only the specific VPC IDs

Answer Correct answer: A — attach a resource policy to the API Gateway API allowing only the specified VPC IDs.

A company has deployed a new REST API by using Amazon API Gateway. The company uses the API to access confidential data. The API must be accessed from only specific VPCs in the company. Which solution will meet these requirements?

  1. Create and attach a resource policy to the API Gateway API. Configure the resource policy to allow only the specific VPC IDs. Correct Answer
  2. Add a security group to the API Gateway API. Configure the inbound rules to allow only the specific VPC IP address ranges.
  3. Create and attach an IAM role to the API Gateway API. Configure the IAM role to allow only the specific VPC IDs.
  4. Add an ACL to the API Gateway API. Configure the outbound rules to allow only the specific VPC IP address ranges.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

API Gateway has no security groups, ACLs, or attachable IAM roles, which eliminates options B, C, and D at their premise (A). The only mechanism API Gateway exposes for caller-based restriction is its resource policy, and the aws:SourceVpc condition is what allows it to permit only specified VPC IDs (A). Srikantha and Ky_24 both described this, noting that resource policies can restrict access based on specific conditions such as VPC IDs.

The API must be reachable only from specific VPCs in the company, which is a caller-identity restriction rather than a network configuration. Amazon API Gateway supports a resource policy on the API, and that policy can be scoped with the aws:SourceVpc or aws:SourceVpce condition so that requests are accepted only when they originate through the specified VPCs or VPC endpoints, with the source VPC also usable as a source for an IAM deny statement. Attaching such a resource policy restricts API access to the named VPCs and nothing else.

Adding a security group to the API Gateway API with inbound rules limited to the VPC IP ranges (B) — API Gateway is a managed service fronted by AWS-owned infrastructure and has no security groups associated with it, so nothing can be attached. Creating an IAM role and attaching it to the API Gateway API (C) — API Gateway does not accept an IAM role in the way the option implies, and an identity-based role on its own would not express a source VPC restriction; the control belongs in a resource policy. Adding an ACL with outbound rules (D) — API Gateway has no ACLs, and outbound rules would not restrict inbound callers in any case, since the requirement is about who may call the API.

Community Discussion (3 comments)

Srikantha 👍 1 Selected: A
Amazon API Gateway supports resource policies, which allow you to control who can access your API based on the source IP address, VPC ID, or even specific IP address ranges. In this case, to restrict access to the API from only specific VPCs, you would create and attach a resource policy to the API Gateway. The resource policy allows you to specify which VPCs (via their VPC IDs) can access the API, ensuring that the API can only be accessed from the designated VPCs. The resource policy is the most efficient and appropriate method for achieving this in API Gateway.
CHRIS12722222 👍 3 Selected: A
https://docs.aws.amazon.com/apigateway/latest/developerguide/apigateway-private-api-create.html
Ky_24 👍 4 Selected: A
Explanation: API Gateway supports resource policies, which can restrict access based on specific conditions, such as VPC IDs or IP ranges. You can attach a resource policy to the API Gateway that allows access only from specific VPCs. This is the most direct and secure way to meet the requirement of allowing access only from specific VPCs.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is that the API be accessible only from specific VPCs, which is a restriction on the caller's origin. Amazon API Gateway supports a resource policy attached to the API, and that policy can use the aws:SourceVpc or aws:SourceVpce condition to permit requests only when they originate from the specified VPCs or VPC endpoints, with the source VPC also usable in a Deny statement for callers outside the set (A). Srikantha noted that API Gateway supports resource policies allowing control of who can access the API based on source IP address, VPC ID, or specific IP ranges, which is exactly the required capability, and Ky_24 explained the same in terms of restricting access with specific conditions such as VPC IDs. CHRIS12722222 cited the AWS documentation on creating a private API for the same mechanism. A is the correct answer.

Why the Other Options Are Wrong

B adds a security group to the API Gateway API and configures inbound rules to allow only the specific VPC IP address ranges. API Gateway is a managed service whose endpoints are fronted by AWS-owned infrastructure, and it has no security groups that can be associated with an API, so there is nothing for this rule to attach to. C creates an IAM role and attaches it to the API Gateway API, configuring it to allow only the specific VPC IDs. API Gateway does not take an attached IAM role as an access-control mechanism in the way described, and an identity-based role alone would not express a source VPC restriction; the mechanism for that is a resource policy with a source VPC condition. D adds an ACL to the API Gateway API and configures outbound rules to allow only the specific VPC IP ranges. API Gateway has no ACLs, and outbound rules would not restrict which callers may invoke the API in any case, since the requirement concerns inbound callers. A is correct.

Community Comment Notes

Community voted A unanimously. Srikantha explained that API Gateway supports resource policies that allow control of who can access the API based on source IP address, VPC ID, or specific IP ranges, and that this restricts access to the specified VPCs. Ky_24 restated the same reasoning about restricting access with specific conditions such as VPC IDs. CHRIS12722222 cited the AWS documentation page for creating a private API. No alternative received support.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide