Deploy the Lambda functions to a private subnet and access S3 through an S3 gateway VPC endpoint
A company has created a set of AWS Lambda functions to automate incident response steps for incidents that occur on Amazon EC2 instances. The Lambda functions need to collect relevant artifacts, such as instance ID and security group configuration. The Lambda functions must then write a summary to an Amazon S3 bucket. The company runs its workloads in a VPC that uses public subnets and private subnets. The public subnets use an internet gateway to access the internet. The private subnets use a NAT gateway to access the internet. All network traffic to Amazon S3 that is related to the incident response process must use the AWS network. This traffic must not travel across the internet. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
An S3 gateway endpoint keeps VPC-to-S3 traffic on the AWS network and is the intended path for private-subnet access to S3. Routing through the NAT gateway (A) sends traffic to the internet, violating the requirement. Co-locating in the same subnet (C) or adding SQS (D) does not by itself keep S3 traffic off the internet. B is correct.
Incident-response Lambda functions in a VPC must read/write an S3 bucket entirely on the AWS network. Deploy them in a private subnet and create an S3 gateway VPC endpoint; traffic to S3 then routes over the AWS backbone via the endpoint instead of the NAT gateway/internet. This meets the 'no internet' requirement without changing code.
Routing S3 through the NAT gateway (A)—that traverses the internet, contradicting the requirement. Assuming same-subnet co-location (C) or an SQS hop (D) solves placement but not the 'S3 traffic must not use the internet' constraint; only a gateway endpoint does.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.