AWS SAA-C03 · Question 07 · Domain 1.2: Secure Workloads
A company has an Amazon S3 bucket containing confidential files. The bucket must only be accessible from a specific Amazon VPC. Which TWO steps are required to enforce this? (Select TWO.)
Answer options:
Create a VPC endpoint for Amazon S3.
Create a NAT Gateway in the VPC.
Add an S3 bucket policy allowing access only from the VPC endpoint.
Configure a Network ACL to block all non-VPC traffic.
Enable S3 Block Public Access.
65 questions · hints · full answers · grading