Verify that the VPC endpoint policy allows access to Amazon S3

Answer Correct answer: D — verify the VPC endpoint policy allows access to Amazon S3, the one layer still unchecked.

A company has configured a gateway VPC endpoint in a VPC. Only Amazon EC2 instances that reside in a single subnet in the VPC can use the endpoint. The company has modified the route table for this single subnet to route traffic to Amazon S3 through the gateway VPC endpoint. The VPC provides internet access through an internet gateway. A security engineer attempts to use instance profile credentials from an EC2 instance to retrieve an object from the S3 bucket, but the attempt fails. The security engineer verifies that the EC2 instance has an IAM instance profile with the correct permissions to access the S3 bucket and to retrieve objects. The security engineer also verifies that the S3 bucket policy is allowing access properly. Additionally, the security engineer verifies that the EC2 instance’s security group and the subnet's network ACLs allow the communication. What else should the security engineer check to determine why the request from the EC2 instance is failing?

  1. Verify that the EC2 instance’s security group does not have an implicit inbound deny rule for Amazon S3.
  2. Verify that the VPC endpoint’s security group does not have an explicit inbound deny rule for the EC2 instance.
  3. Verify that the internet gateway is allowing traffic to Amazon S3.
  4. Verify that the VPC endpoint policy is allowing access to Amazon S3. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A gateway VPC endpoint enforces its own endpoint policy in addition to IAM and bucket policies; if the endpoint policy does not allow the S3 actions (or explicitly denies), the request fails even when everything else is correct. Security groups do not apply to gateway endpoints (so B is moot), and the internet gateway is not in the path for endpoint traffic (C is wrong). D is the correct missing check.

All the usual layers check out (instance-profile IAM, S3 bucket policy, SG, NACL), yet the GetObject via the gateway endpoint still fails. The missing layer is the VPC endpoint policy: a gateway endpoint has its own resource policy that must also allow the S3 actions, and an implicit or explicit deny there overrides the other allows. Verifying the endpoint policy permits S3 access is the next check.

Checking the endpoint's security group (B)—gateway endpoints do not have security groups; only interface endpoints do. Checking the internet gateway (C)—traffic to S3 via a gateway endpoint does not traverse the IGW. The overlooked control is the endpoint policy (D), which can deny even when IAM and bucket policies allow.

Community Discussion (6 comments)

FlyingHawk 👍 1 Selected: D
Security Group only has allowed rules. A and B are incorrect. gateway endpoint does not use the internet, so C is incorrect. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-s3.html
Pmktechno 👍 1 Selected: D
Even if the IAM instance profile, S3 bucket policy, security group, and network ACLs are correctly configured, the VPC endpoint policy must also allow access to the S3 bucket. If the endpoint policy is too restrictive, it could prevent the EC2 instance from accessing S3, causing the request to fail.
mzeynalli 👍 1 Selected: D
VPC endpoint policy must be configured to allow access to the S3 bucket explicitly.
dabber 👍 1 Selected: D
SG's don't have deny rules...
mzeynalli 👍 1 Selected: D
NOT B!!! B. VPC endpoint’s security group: Gateway VPC endpoints do not have security groups. Security groups apply to certain AWS resources (like EC2 instances and interface endpoints), but not to gateway endpoints. Therefore, option D is the most appropriate answer, as the VPC endpoint policy must be configured to allow access to the S3 bucket explicitly.
koo_kai 👍 1 Selected: D
Gateway VPC endpoint

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A gateway VPC endpoint evaluates its own endpoint policy alongside the caller's IAM permissions and the S3 bucket policy. If the endpoint policy does not grant the required S3 permissions, the request is denied regardless of the other layers. Since IAM, bucket policy, SG, and NACL are already confirmed correct, the endpoint policy is the remaining control to verify—making D the right next check.

Why the Other Options Are Wrong

A checks the instance SG for an implicit S3 deny, but SGs have no implicit denies and the SG was already verified. B references a security group on the gateway endpoint, which does not exist—gateway endpoints are not secured by security groups. C checks the internet gateway, but endpoint traffic to S3 does not go through the IGW. D is correct.

Community Comment Notes

Community voted D (100). Commenters noted security groups only have allow rules and gateway endpoints have no security group, and that the IGW is not in the path—so the endpoint policy is the control that can still deny access. D confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide