Reach a cross-account S3 data lake through a gateway endpoint and an access point bucket policy

Answer Correct answers: A, E — Create a gateway VPC endpoint for S3 and add a bucket policy statement conditioned on a valid S3 access point ARN.

A company is collecting data from a large set of IoT devices. The data is stored in an Amazon S3 data lake. Data scientists perform analytics on Amazon EC2 instances that run in two public subnets in a VPC in a separate AWS account. The data scientists need access to the data lake from the EC2 instances. The EC2 instances already have an assigned role with permissions to access Amazon S3. According to company policies, only authorized networks are allowed to have access to the IoT data. Which combination of steps should a solutions architect take to meet these requirements? (Choose two.)

  1. Create a gateway VPC endpoint for Amazon S3 in the data scientists’ VPC. Correct Answer
  2. Create an S3 access point in the data scientists' AWS account for the data lake.
  3. Update the EC2 instance role. Add a policy with a condition that allows the s3:GetObject action when the value for the s3:DataAccessPointArn condition key is a valid access point ARN.
  4. Update the VPC route table to route S3 traffic to an S3 access point.
  5. Add an S3 bucket policy with a condition that allows the s3:GetObject action when the value for the s3:DataAccessPointArn condition key is a valid access point ARN. Correct Answer

Community Votes

BE
53%
AE
47%

53% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A gateway VPC endpoint keeps the S3 traffic on the AWS network and away from the public internet, which is what satisfies the authorized network policy, and an access point ARN condition in the bucket policy scopes access to requests that arrive through that access point.

Data scientists run EC2 instances in public subnets of a VPC in a different AWS account from the S3 data lake, and their instances already have a role that can access S3. Company policy allows only authorized networks to reach the IoT data.

Adding a route in the VPC route table pointing to an S3 access point. Access points are addressed through the S3 API endpoint, not through a route table target, so there is no route to create. Note also that a bucket policy can be applied to an access point directly, which is what makes the access point ARN condition usable.

Community Discussion (18 comments)

Deztroyer88 👍 2 Selected: AE
A gateway VPC endpoint allows EC2 instances to access S3 privately without using the public internet. E. The S3 bucket policy ensures that only authorized access via the S3 access point is permitted. B is wrong because S3 Access Points are tied to the bucket’s AWS account, not the requester's AWS account. The access point should be created in the same AWS account as the S3 data lake, not in the data scientists’ account.
Spike2020 👍 3 Selected: AE
A: Gateway VPC endpoints provide secure access to S3 without requiring internet access. Can be used in a multi-account setting. E: Bucket policies can restrict access to specific VPC endpoints. Not B: While S3 access points can be useful, they're not necessary in this scenario where the primary requirement is network-level access control.
AzureDP900 👍 2
B: Creating an S3 access point in the data scientists' AWS account provides a secure and controlled way to expose the data lake to EC2 instances. The access point allows you to manage who can access the bucket, and you can configure the bucket policy to include conditions that restrict access. E: Adding an S3 bucket policy with a condition that allows the s3:GetObject action when the value for the s3:DataAccessPointArn condition key is a valid access point ARN provides additional security and control over who can access the data lake. This ensures that only authorized networks (in this case, the data scientists' AWS account) can access the bucket.
doobc 👍 1
BE. https://aws.amazon.com/blogs/storage/setting-up-cross-account-amazon-s3-access-with-s3-access-points/
sam2ng 👍 2
I feel the combination of A,B and E would be the correct answer
kgpoj 👍 4
This question is really bad. It feels like if A is selected, then E needs to be adjusted to enable access between VPC endpoints and the bucket directly Or if B is selected, then B needs to be reworded to say creating access point in data lake account, then E would be valid without any modification
backbencher2022 👍 4 Selected: BE
B & E are correct options. A isn't correct because gateway VPC endpoint doesn't work outside of VPC. In this question, we are talking about 2 different accounts which implies 2 different VPCs as well
kgpoj 👍 2 Selected: AE
S3 Access Point should be created in destination account. You need VPC endpoint to keep the network private. This question might just assumed that the S3 access point is already created in destination account
zolthar_z 👍 3 Selected: BE
S3 access point is used If you want to share your bucket with other accounts
dzidis 👍 3 Selected: BE
Gateway endpoint do not work cross account, so BE. owever, gateway endpoints do not allow access from on-premises networks, from peered VPCs in other AWS Regions, or through a transit gateway. For those scenarios, you must use an interface endpoint, which is available for an additional cost. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-s3.html
RotterDam 👍 3 Selected: BE
Anyone who is picking A/E - please realize DataAccessPointArn ONLY WORKS when there is an access point created. A does NOT mention creating an Access Point. B is completely possible and combine with E restricts all traffic coming from the VPC that has the acccess point mentioned in B. B+E is the correct answer
luuthang2011 👍 1
a,d gateway VPC endpoint needs config route table
vip2 👍 1 Selected: AE
A, E are correct
gfhbox0083 👍 2 Selected: AE
A, E for sure. Only authorized networks are allowed to have access to the IoT data.
c22ddd8 👍 3 Selected: BE
Need access from different AWS account with restrictions. So it is BE
Alagong 👍 4 Selected: AE
A. This step ensures that the traffic between the EC2 instances and the S3 data lake does not traverse the public internet, thereby meeting security requirements and reducing latency. E. This step ensures that the access to the data lake is restricted according to company policies. It leverages an S3 bucket policy to enforce access control based on specific conditions, thereby providing an additional layer of security.
Alagong 👍 1
A. This step ensures that the traffic between the EC2 instances and the S3 data lake does not traverse the public internet, thereby meeting security requirements and reducing latency. C. This step ensures that the access to the data lake is restricted according to company policies. It leverages an S3 bucket policy to enforce access control based on specific conditions, thereby providing an additional layer of security.
kupo777 👍 2
B S3 access points allow fine-grained control of access policies and network settings for specific S3 buckets. E s3:DataAccessPointArn must be used to set permissions on the S3 bucket side for going through the access point. role settings in C do not have settings to determine the access point on the bucket side.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A gateway VPC endpoint for S3 provides a private path from the VPC to Amazon S3 over the AWS network, so the EC2 instances in public subnets no longer send that traffic to the public internet, which satisfies the policy that only authorized networks may reach the IoT data. On the authorization side, adding a statement to the S3 bucket policy that allows s3:GetObject when the s3:DataAccessPointArn condition key matches a valid access point ARN restricts data access to requests that come through the designated access point, and the existing instance role already carries S3 permissions so no role change is needed. Together these give private network access and access-point-scoped authorization.

Why the Other Options Are Wrong

B: An S3 access point is an S3 resource, not a network construct, and creating one in the data scientists' account adds an indirection without providing private network access on its own. C: Modifying the instance role with an access point ARN condition duplicates the same restriction that the bucket policy already expresses, and the instance role is explicitly stated to already have the S3 permissions needed. D: Route tables route to network targets such as VPC endpoints or gateways, not to S3 access points, so this step is not meaningful.

Community Comment Notes

The community was split 53 to 47 between B and E, with A and E and A and B each represented among the votes. The strongest arguments on either side converged on the same two real requirements: private network access, which only a gateway endpoint provides, and access-point-scoped authorization. The AWS guidance for setting up cross-account S3 access with access points and the recurring observation that bucket policies can restrict access via access point conditions are what settle the pairing.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide