Write to a cross-account S3 bucket privately using a gateway VPC endpoint

Answer Correct answer: D — a gateway VPC endpoint for S3 in Account A keeps the cross-account write on the AWS private network with minimal overhead.

A company has two AWS accounts: Account A and Account B. Each account has a VPC. An application that runs in the VPC in Account A needs to write to an Amazon S3 bucket in Account B. The application in Account A already has permission to write to the S3 bucket in Account B. The application and the S3 bucket are in the same AWS Region. The company cannot send network traffic over the public internet. Which solution will meet these requirements?

  1. In both accounts, create a transit gateway and VPC attachments in a subnet in each Availability Zone. Update the VPC route tables.
  2. Deploy a software VPN appliance in Account A. Create a VPN connection between the software VPN appliance and a virtual private gateway in Account B.
  3. Create a VPC peering connection between the VPC in Account A and the VPC in Account B. Update the VPC route tables, network ACLs, and security groups to allow network traffic between the peered IP ranges
  4. In Account A, create a gateway VPC endpoint for Amazon S3. Update the VPC route table in Account A. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

S3 gateway endpoints are free, scale automatically, and keep S3 traffic on the AWS backbone without a transit gateway, VPN, or peering relationship. Because the bucket already grants cross-account write permission, only the private route in Account A is needed; the traffic stays within AWS and never traverses the public internet.

An app in Account A's VPC must write to an S3 bucket in Account B in the same Region without using the public internet. The bucket policy already grants the app write permission. A gateway VPC endpoint for Amazon S3 in Account A routes S3 traffic over the AWS private network (no internet gateway or NAT needed), keeping the traffic off the public internet with the least operational overhead.

Choosing VPC peering or a transit gateway/VPN. Those also avoid the public internet but add cost and operational overhead for what is a single S3 write path; a gateway endpoint is the simpler, lower-latency, no-cost solution when only S3 access is required.

Community Discussion (6 comments)

VerRi 👍 2 Selected: D
Both C and D should work, but considering the scenario, it only requires writing to S3, and D has less operational overhead and better performance.
adit 👍 1 Selected: C
Option C
cumzle_com 👍 1 Selected: D
By using a gateway VPC endpoint, the solution remains within the AWS network, ensuring low latency and secure traffic flow without the need for additional infrastructure and complexity
grekh001 👍 1
D. However, gateway endpoints do not allow access from on-premises networks, from peered VPCs in other AWS Regions, or through a transit gateway. For those scenarios, you must use an interface endpoint, which is available for an additional cost. https://docs.aws.amazon.com/vpc/latest/privatelink/vpc-endpoints-s3.html
Certified101 👍 4 Selected: D
D 100000%%
Nash101 👍 2
C A. Transit Gateway: While transit gateways can connect multiple VPCs, they are more complex to set up and manage compared to VPC peering for this specific scenario. They might be a better choice for intricate multi-account VPC connectivity needs. B. Software VPN: A software VPN creates a secure tunnel over the internet, which violates the requirement of avoiding public internet traffic. Additionally, VPNs can introduce performance overhead and management complexity. D. Gateway VPC Endpoint for S3: This option utilizes a Gateway VPC endpoint for S3 access within the VPC in Account A. However, it only allows access to S3 within the same account (Account A). The application needs access to the S3 bucket in a different account (Account B).

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The requirement is simply private, internet-free access from Account A to an S3 bucket in Account B. A gateway VPC endpoint for Amazon S3 in Account A's VPC routes the PutObject traffic over the AWS network, satisfying "no public internet" with zero additional infrastructure. The existing bucket policy already authorizes the cross-account write, so no peering or VPN is needed.

Why the Other Options Are Wrong

A (transit gateway) and C (VPC peering) would also keep traffic private but introduce unnecessary cost and management overhead for a single S3 path; peering also would not by itself prevent internet routing without the endpoint. B is wrong because a software VPN tunnels over the public internet, directly violating the no-public-internet constraint.

Community Comment Notes

Community strongly favored D ("100000%%"), noting both C and D work but D has less overhead and better performance. A commenter added the caveat that gateway endpoints do not reach on-prem or other-Region peered VPCs—irrelevant here since the bucket is same-Region.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide