AWS CLI is not installed , you should install it
you can have have jump server or nat gateway
you can use VPC gateway endpoint for S3
ZRS acts like a failover cluster by keeping your data synced across multiple zones in one region for automatic zone-level protection, while GZRS adds protection by also copying data to a second region to handle full regional failures.
ARN-Amazon Resourve Name is a Unique identifier assigned for each object/resources in AWS