AWS SAA-C03 · Question 06 · Domain 1.1: Secure Access
A company wants to restrict access to an Amazon S3 bucket so that only requests originating from a specific Amazon Virtual Private Cloud (VPC) are allowed. <br/><br/>Which TWO actions must a solutions architect take to meet this requirement? (Select TWO.)
Answer options:
Create a VPC endpoint for Amazon S3 in the VPC.
Create a NAT gateway in a public subnet.
Add a bucket policy to the S3 bucket that denies access unless the aws:sourceVpce condition matches the VPC endpoint.
Configure an IAM policy for the EC2 instances to allow S3 access.
Modify the S3 bucket ACL to only allow the VPC CIDR block.
65 questions · hints · full answers · grading