CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security engineer is reviewing the access policies for an AWS S3 bucket that stores highly sensitive customer data. The current policy allows public read access to all objects by default. This configuration poses a significant security risk. To remediate this, the engineer needs to ensure that access is restricted to authenticated users within the company's AWS account only, while preventing any public access. Which action should the engineer take?

  1. AEnable S3 Object Lock on the bucket to prevent accidental deletions.
  2. BConfigure server-side encryption with AWS KMS (SSE-KMS) for all objects in the bucket.
  3. CSet up a CloudFront distribution with OAI to serve content privately from the S3 bucket.
  4. DApply a bucket policy that explicitly denies public access and grants access only to a specific IAM role.
Show answer & explanation

Correct answer: D. Apply a bucket policy that explicitly denies public access and grants access only to a specific IAM role.

A bucket policy is the primary mechanism to control access to an S3 bucket and its objects. By explicitly denying public access and granting access only to specific IAM roles or users, the engineer can enforce the 'authenticated users within the company's AWS account only' requirement and prevent public exposure.

Why the other options are wrong

  • A. S3 Object Lock ensures immutability but does not control who can access the objects; it only prevents deletion or modification.
  • B. SSE-KMS encrypts data at rest, protecting its confidentiality, but it does not control network access or prevent public access if the bucket policy allows it.
  • C. CloudFront with OAI (Origin Access Identity) is used to restrict public access when S3 content is served via a CDN, but the core problem is public access directly to the S3 bucket itself, which needs a bucket policy fix.

S3 Bucket Policies

Resource-based access policies attached directly to an S3 bucket to control who has access to the bucket and its objects.

  • JSON-based policy language.
  • Can grant or deny permissions.
  • Evaluated with IAM policies for final access decisions.

Memory trick: Bucket policies are the bouncers for your S3 club.

More Security questions