QuestionQ21

Infrastructure Security

A company uses two AWS accounts: Account A and Account B. Each account contains a VPC. An application running in the VPC in Account A must write to an Amazon S3 bucket in Account B. The application in Account A already has permission to write to the S3 bucket in Account B.

The application and the S3 bucket are located in the same AWS Region. The company must not send network traffic across the public internet.

Which solution satisfies these requirements?

Explanation

An Amazon S3 gateway VPC endpoint in Account A provides private, route-table-based access from that VPC to Amazon S3 in the same Region, without requiring an internet gateway or NAT device. The bucket’s account does not require VPC-to-VPC connectivity; access is controlled by the existing S3 permissions and the endpoint policy. AWS documents that gateway endpoints support Amazon S3 and are available only in the Region in which they are created.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!