CompTIA Cloud+ (CV0-004)SecurityHard
A cloud security architect is reviewing the access controls for a critical storage bucket containing sensitive customer data. The current policy allows an external third-party application, identified by its AWS account ID, to write objects to the bucket. The architect wants to implement the principle of least privilege, ensuring the third-party application can only perform the specific 's3:PutObject' action and nothing else, and only when the request comes from a specific VPC endpoint. Which type of policy and specific condition key should be used to restrict access to only 's3:PutObject' via a specified VPC endpoint?
- ABucket Policy with `aws:SourceVpc` and `aws:SourceVpce` conditions
- BIAM Role Policy with `s3:GetObject` and `aws:Vpc` condition
- CBucket ACL with `s3:PutObject` and `aws:SourceVpc` condition
- DIAM User Policy with `aws:SourceIp` condition
Show answer & explanationAnswer & explanation
Correct answer: A. Bucket Policy with `aws:SourceVpc` and `aws:SourceVpce` conditions
A Bucket Policy is used to control access to S3 buckets. The `aws:SourceVpc` and `aws:SourceVpce` condition keys are specifically designed to restrict access to a bucket only when the request originates from a specified VPC or VPC endpoint, enforcing private and secure access for the 's3:PutObject' action.
Why the other options are wrong
- B. IAM Role Policies are attached to roles, but the primary control for S3 buckets is often a bucket policy. `s3:GetObject` is wrong, and `aws:Vpc` is not a standard condition key for this purpose; `aws:SourceVpc` is correct.
- C. Bucket ACLs (Access Control Lists) are less granular and don't support condition keys like `aws:SourceVpc` for VPC endpoint restrictions; they are mostly for granting basic read/write permissions to other AWS accounts.
- D. IAM User Policies apply to users, not directly to buckets for cross-account access, and `aws:SourceIp` is for public IPs, not VPC endpoints.
S3 Bucket Policy with VPC Endpoint Condition
An AWS S3 Bucket Policy that uses condition keys like `aws:SourceVpc` and `aws:SourceVpce` to restrict access to the bucket only when requests originate from a specified Virtual Private Cloud (VPC) or VPC Endpoint.
- Enforces private access to S3 from within a VPC.
- Prevents data exfiltration by blocking public internet access.
- Increases security and compliance for sensitive S3 data.
Memory trick: Bucket Policies Block Bad Broad Browsing.