AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A company discovers that an Amazon S3 bucket containing sensitive documents was accidentally made public through a misconfigured bucket policy. The security team wants a setting that prevents any S3 bucket in the account from ever becoming publicly accessible, regardless of future policy or ACL changes. Which feature should they enable?

  1. AAmazon Macie sensitive data discovery
  2. BAWS Config conformance pack for S3 encryption
  3. CS3 Block Public Access at the account level
  4. DS3 Object Lock in compliance mode
Show answer & explanation

Correct answer: C. S3 Block Public Access at the account level

S3 Block Public Access provides account-level and bucket-level settings that override any bucket policies or ACLs attempting to grant public access, ensuring buckets stay private even if misconfigured later.

Why the other options are wrong

  • A. Macie discovers sensitive data but does not control public access settings
  • B. Config can detect non-compliant encryption but does not block public access itself
  • D. Object Lock prevents deletion/overwrite of objects, unrelated to public access

S3 Block Public Access

An S3 security feature that overrides bucket policies and ACLs to prevent public access, settable at the account or bucket level.

  • Can be enabled account-wide to protect all buckets
  • Overrides any future public bucket policy or ACL changes
  • Recommended as a default security baseline for S3

Memory trick: A locked bucket lid stays shut no matter who tries to open it.

More Security and Compliance questions