Verify that the VPC endpoint policy allows access to Amazon S3
A company has configured a gateway VPC endpoint in a VPC. Only Amazon EC2 instances that reside in a single subnet in the VPC can use the endpoint. The company has modified the route table for this single subnet to route traffic to Amazon S3 through the gateway VPC endpoint. The VPC provides internet access through an internet gateway. A security engineer attempts to use instance profile credentials from an EC2 instance to retrieve an object from the S3 bucket, but the attempt fails. The security engineer verifies that the EC2 instance has an IAM instance profile with the correct permissions to access the S3 bucket and to retrieve objects. The security engineer also verifies that the S3 bucket policy is allowing access properly. Additionally, the security engineer verifies that the EC2 instance’s security group and the subnet's network ACLs allow the communication. What else should the security engineer check to determine why the request from the EC2 instance is failing?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A gateway VPC endpoint enforces its own endpoint policy in addition to IAM and bucket policies; if the endpoint policy does not allow the S3 actions (or explicitly denies), the request fails even when everything else is correct. Security groups do not apply to gateway endpoints (so B is moot), and the internet gateway is not in the path for endpoint traffic (C is wrong). D is the correct missing check.
All the usual layers check out (instance-profile IAM, S3 bucket policy, SG, NACL), yet the GetObject via the gateway endpoint still fails. The missing layer is the VPC endpoint policy: a gateway endpoint has its own resource policy that must also allow the S3 actions, and an implicit or explicit deny there overrides the other allows. Verifying the endpoint policy permits S3 access is the next check.
Checking the endpoint's security group (B)—gateway endpoints do not have security groups; only interface endpoints do. Checking the internet gateway (C)—traffic to S3 via a gateway endpoint does not traverse the IGW. The overlooked control is the endpoint policy (D), which can deny even when IAM and bucket policies allow.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.