Restore S3 GetObject access by fixing ListBucket, KMS Decrypt, and the gateway-endpoint bucket policy
A company has an application that needs to get objects from an Amazon S3 bucket. The application runs on Amazon EC2 instances. All the objects in the S3 bucket are encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The resources in the VPC do not have access to the internet and use a gateway VPC endpoint to access Amazon S3. The company discovers that the application is unable to get objects from the S3 bucket. Which factors could cause this issue? (Choose three.)
Community Votes
100% of anonymous learners picked answer ADE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Reading a KMS-encrypted object through a gateway endpoint needs three permissions aligned: S3 read/list permission on the instance profile, kms:Decrypt on the CMK key policy for that principal, and a bucket policy that permits the gateway endpoint. ListParts is for multipart uploads and ListKeys is for key enumeration—neither affects GetObject. A, D, E are the failure factors.
An EC2 app reaches S3 only through a gateway VPC endpoint, and objects are KMS-CMK encrypted. Three things can block GetObject: the instance profile lacks s3:ListBucket (needed to enumerate/resolve the objects it fetches), the KMS key policy does not grant kms:Decrypt to the instance profile (required to decrypt the object on read), and the S3 bucket policy does not allow access from the gateway VPC endpoint (so even the endpoint path is denied). s3:ListParts (B) and kms:ListKeys (C) are unrelated to reading objects.
Picking C (missing kms:ListKeys)—ListKeys only lists key IDs and is not required to decrypt an object. Picking B (missing s3:ListParts)—ListParts is for multipart upload completion, irrelevant to reading. The real blockers are ListBucket scope, kms:Decrypt, and the endpoint bucket policy.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.