passdrill
AWS SAA-C03 · VPC & Networking · Card 038/038 medium

A team creates a new interface VPC endpoint for an AWS service and does not attach any custom endpoint policy to it. Immediately after creation, what access does the endpoint grant by default?

  1. No access at all; every interface VPC endpoint starts with an implicit deny-all policy and requires a custom policy to be attached before any traffic is allowed through it
  2. Full access; the default endpoint policy allows all principals to perform all actions on the service through the endpoint, equivalent to how the service behaves without a VPC endpoint at all, subject to any other IAM or resource policies that would otherwise apply
  3. Access limited to the AWS account that owns the VPC, but no other accounts, even if those other accounts' principals would otherwise be authorized by IAM
  4. Access limited strictly to read-only API actions until a custom policy explicitly grants write actions
Next card → Shuffle