Reach a cross-account S3 data lake through a gateway endpoint and an access point bucket policy
A company is collecting data from a large set of IoT devices. The data is stored in an Amazon S3 data lake. Data scientists perform analytics on Amazon EC2 instances that run in two public subnets in a VPC in a separate AWS account. The data scientists need access to the data lake from the EC2 instances. The EC2 instances already have an assigned role with permissions to access Amazon S3. According to company policies, only authorized networks are allowed to have access to the IoT data. Which combination of steps should a solutions architect take to meet these requirements? (Choose two.)
Community Votes
53% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A gateway VPC endpoint keeps the S3 traffic on the AWS network and away from the public internet, which is what satisfies the authorized network policy, and an access point ARN condition in the bucket policy scopes access to requests that arrive through that access point.
Data scientists run EC2 instances in public subnets of a VPC in a different AWS account from the S3 data lake, and their instances already have a role that can access S3. Company policy allows only authorized networks to reach the IoT data.
Adding a route in the VPC route table pointing to an S3 access point. Access points are addressed through the S3 API endpoint, not through a route table target, so there is no route to create. Note also that a bucket policy can be applied to an access point directly, which is what makes the access point ARN condition usable.
Community Discussion (18 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A gateway VPC endpoint for S3 provides a private path from the VPC to Amazon S3 over the AWS network, so the EC2 instances in public subnets no longer send that traffic to the public internet, which satisfies the policy that only authorized networks may reach the IoT data. On the authorization side, adding a statement to the S3 bucket policy that allows s3:GetObject when the s3:DataAccessPointArn condition key matches a valid access point ARN restricts data access to requests that come through the designated access point, and the existing instance role already carries S3 permissions so no role change is needed. Together these give private network access and access-point-scoped authorization.Why the Other Options Are Wrong
B: An S3 access point is an S3 resource, not a network construct, and creating one in the data scientists' account adds an indirection without providing private network access on its own. C: Modifying the instance role with an access point ARN condition duplicates the same restriction that the bucket policy already expresses, and the instance role is explicitly stated to already have the S3 permissions needed. D: Route tables route to network targets such as VPC endpoints or gateways, not to S3 access points, so this step is not meaningful.Community Comment Notes
The community was split 53 to 47 between B and E, with A and E and A and B each represented among the votes. The strongest arguments on either side converged on the same two real requirements: private network access, which only a gateway endpoint provides, and access-point-scoped authorization. The AWS guidance for setting up cross-account S3 access with access points and the recurring observation that bucket policies can restrict access via access point conditions are what settle the pairing.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →