Deploy the Lambda functions to a private subnet and access S3 through an S3 gateway VPC endpoint

Answer Correct answer: B — deploy the Lambda functions to a private subnet and access S3 through an S3 gateway VPC endpoint, keeping traffic on the AWS network.

A company has created a set of AWS Lambda functions to automate incident response steps for incidents that occur on Amazon EC2 instances. The Lambda functions need to collect relevant artifacts, such as instance ID and security group configuration. The Lambda functions must then write a summary to an Amazon S3 bucket. The company runs its workloads in a VPC that uses public subnets and private subnets. The public subnets use an internet gateway to access the internet. The private subnets use a NAT gateway to access the internet. All network traffic to Amazon S3 that is related to the incident response process must use the AWS network. This traffic must not travel across the internet. Which solution will meet these requirements?

  1. Deploy the Lambda functions to a private subnet in the VPC. Configure the Lambda functions to access the S3 service through the NAT gateway.
  2. Deploy the Lambda functions to a private subnet in the VPC. Create an S3 gateway endpoint to access the S3 service. Correct Answer
  3. Deploy the S3 bucket and the Lambda functions in the same private subnet. Configure the Lambda functions to use the default endpoint for the S3 service.
  4. Deploy an Amazon Simple Queue Service (Amazon SQS) queue and the Lambda functions in the same private subnet. Configure the Lambda functions to send data to the SQS queue. Configure the SQS queue to send data to the S3 bucket.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An S3 gateway endpoint keeps VPC-to-S3 traffic on the AWS network and is the intended path for private-subnet access to S3. Routing through the NAT gateway (A) sends traffic to the internet, violating the requirement. Co-locating in the same subnet (C) or adding SQS (D) does not by itself keep S3 traffic off the internet. B is correct.

Incident-response Lambda functions in a VPC must read/write an S3 bucket entirely on the AWS network. Deploy them in a private subnet and create an S3 gateway VPC endpoint; traffic to S3 then routes over the AWS backbone via the endpoint instead of the NAT gateway/internet. This meets the 'no internet' requirement without changing code.

Routing S3 through the NAT gateway (A)—that traverses the internet, contradicting the requirement. Assuming same-subnet co-location (C) or an SQS hop (D) solves placement but not the 'S3 traffic must not use the internet' constraint; only a gateway endpoint does.

Community Discussion (3 comments)

phmeeeee 👍 1 Selected: B
B - Lambda in private subnet and use S3 via vpc gateway endpoint.
navid1365 👍 2 Selected: B
B: AWS PrivateLink and S3 Gateway Endpoint allow you to keep traffic between your VPC and S3 within the AWS network, avoiding the public internet.
aescudero51 👍 2 Selected: B
Answer is B A. NAT Gateway: While Lambda functions in a private subnet can access the internet through a NAT gateway, it's not recommended for S3 access due to potential latency and security concerns. S3 Gateway Endpoint provides a more secure and performant way. C. Same Subnet: Deploying S3 bucket and Lambda functions in the same subnet wouldn't require a special endpoint, but it's not a best practice. S3 buckets are regionally accessible services, keeping them separate from compute resources offers better security isolation. D. SQS Queue: While SQS can be used for communication between services, it's an unnecessary step in this scenario. The Lambda functions can directly write the incident response summary to the S3 bucket using the S3 Gateway Endpoint.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Placing the Lambda functions in a private subnet and adding an S3 gateway VPC endpoint directs all S3 API calls over the AWS network via the endpoint's prefix-list route, never touching the NAT gateway or public internet. This satisfies the mandate that incident-response S3 traffic stays on the AWS network, with no code changes.

Why the Other Options Are Wrong

A sends S3 traffic through the NAT gateway to the internet, violating the requirement. C merely co-locates resources in a subnet but still uses the default (internet) path without an endpoint. D inserts SQS but does not keep S3 access off the internet. B is the correct network path.

Community Comment Notes

Community voted B (100). Commenters noted Lambda in a private subnet plus an S3 gateway endpoint keeps traffic between the VPC and S3 on the AWS network, avoiding the public internet. B confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide