Q: 13
A company hosts its application on several Amazon EC2 instances inside a VPC. The company creates
a dedicated Amazon S3 bucket for each customer to store their relevant information in Amazon S3.
The company wants to ensure that the application running on EC2 instances can securely access only
the S3 buckets that belong to the company's AWS account.
Which solution will meet these requirements with the LEAST operational overhead?
Options
Discussion
Its A, pretty sure. Gateway endpoint keeps S3 traffic in the AWS backbone, and using IAM instance profile is standard for controlling bucket access. Much less hassle than NAT gateway setups. Official AWS docs and exam practice questions both push this combo for least overhead.
Setting up the S3 gateway endpoint and then restricting access via instance profile policy is A. This keeps things simple and secure.
Yeah, A makes sense here. Using the gateway endpoint plus a tight IAM policy on the instance profile keeps it private, avoids NAT costs, and is easy to maintain. Pretty sure that's what AWS recommends for this setup.
Be respectful. No spam.
Question 13 of 35