Which additional steps should the solutions architect take to meet these requirements?

1 Comment

  1. Marilyn
    Author

    I would say the answer is:
    Assign an endpoint policy to the VPC endpoint that restricts access to a specific S3 bucket. Attach a bucket policy to the S3 bucket that grants access to the VPC endpoint. Assign an IAM role to the application EC2 instances and only allow access to this role in the S3 bucket’s policy.

Leave a Reply to Marilyn Cancel reply

Your email address will not be published. Required fields are marked *

one × 1 =