AnswerCorrect answer: A, C — an S3 gateway endpoint and a KMS interface endpoint with private DNS keep all cross-account API calls on the AWS network.
A company has a batch-processing system that uses Amazon S3, Amazon EC2, and AWS Key Management Service (AWS KMS). The system uses two AWS accounts: Account A and Account B. Account A hosts an S3 bucket that stores the objects that will be processed. The S3 bucket also stores the results of the processing. All the S3 bucket objects are encrypted by a KMS key that is managed in Account A. Account B hosts a VPC that has a fleet of EC2 instances that access the S3 bucket in Account A by using statements in the bucket policy. The VPC was created with DNS hostnames enabled and DNS resolution enabled. A security engineer needs to update the design of the system without changing any of the system's code. No AWS API calls from the batch-processing EC2 instances can travel over the internet. Which combination of steps will meet these requirements? (Choose two.)
In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket. Correct Answer
In the Account B VPC, create an interface VPC endpoint for Amazon S3. For the interface VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, s3:PutObject, and s3:PutObjectAcl actions for the S3 bucket.
In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned on for the endpoint. Correct Answer
In the Account B VPC, create an interface VPC endpoint for AWS KMS. For the interface VPC endpoint, create a resource policy that allows the kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey actions for the KMS key. Ensure that private DNS is turned off for the endpoint.
In the Account B VPC, verify that the S3 bucket policy allows the s3:PutObjectAcl action for cross-account use. In the Account B VPC, create a gateway VPC endpoint for Amazon S3. For the gateway VPC endpoint, create a resource policy that allows the s3:GetObject, s3:ListBucket, and s3:PutObject actions for the S3 bucket.
Community Votes
AC
100%
100% of anonymous learners picked answer AC.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
S3 is accessed from a VPC through a gateway endpoint (A), not an interface endpoint. KMS is accessed through an interface endpoint (C) and private DNS must be on so the Kms* API hostnames resolve to the private endpoint IP rather than the public one—otherwise the code would still reach KMS publicly. Disabling private DNS (D) would break transparent resolution. A+C is correct; the BC variant is wrong because S3 uses a gateway endpoint.
Account B's EC2 fleet reads/writes an Account A S3 bucket (KMS-encrypted) and must make no AWS API calls over the internet, with no code change. Create an S3 gateway VPC endpoint in Account B's VPC (S3 is reached via gateway endpoints) and an interface VPC endpoint for KMS with private DNS enabled (so the KMS API resolves to the private endpoint). Both keep S3 and KMS traffic on the AWS network.
Choosing an interface endpoint for S3 (B)—S3 uses gateway endpoints from a VPC, not interface endpoints. Turning private DNS off for the KMS interface endpoint (D)—without private DNS the KMS SDK still resolves the public hostname and traffic would leave the VPC. A+C (gateway S3 + interface KMS with private DNS) is the correct pair.
Community Discussion (7 comments)
nznzwell👍 1Selected: AC
All the comments regarding s3 cannot be accessed by an interface endpoint is wrong - instead, s3 can use both gateway endpoints and interface endpoints: https://docs.aws.amazon.com/AmazonS3/latest/userguide/privatelink-interface-endpoints.html B is not correct as the question does not mention any connectivity between Account A and B so private routing is not possible.
jdx000👍 1Selected: AC
A and C
komik_101👍 2Selected: AC
I will going to AC, when I look at the question , I saw "fleet of EC2" this means Account B have many EC2. Go to link. you will see many topology, and you will understand what I mean. https://aws.amazon.com/tr/blogs/architecture/choosing-your-vpc-endpoint-strategy-for-amazon-s3/
3e88bd8👍 1
AC: Amazon S3 uses a gateway VPC endpoint rather than an interface VPC endpoint for access from a VPC.
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
An S3 gateway VPC endpoint (A) routes Account B's S3 API calls over the AWS network via the endpoint's prefix-list route, avoiding the internet; S3 is specifically designed for gateway endpoints. A KMS interface VPC endpoint with private DNS enabled (C) makes the Kms* API hostnames resolve to private IPs inside the VPC, so Decrypt/GenerateDataKey calls stay off the public internet—and no application code changes because the SDK uses the same endpoint names. A and C meet both requirements.
Why the Other Options Are Wrong
B uses an interface endpoint for S3, which is not how S3 is reached from a VPC (gateway endpoint is). D turns private DNS off for the KMS endpoint, so the KMS API would still resolve publicly and traffic would traverse the internet, violating the requirement. A and C are correct.
Community Comment Notes
Community voted A,C (100). Commenters clarified S3 uses a gateway endpoint and KMS an interface endpoint with private DNS on; one dissenter proposed B,C but was corrected that S3 is gateway-based. A,C confirmed.