Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityEasy

A cloud security engineer discovers that several Amazon S3 buckets containing sensitive company data are publicly accessible. This misconfiguration poses a significant data breach risk. What is the immediate and most critical best practice to apply to these S3 buckets?

  1. AConfigure cross-region replication.
  2. BEnable versioning on the buckets.
  3. CEnable server-side encryption with customer-provided keys.
  4. DRestrict public access to the buckets.
Show answer & explanation

Correct answer: D. Restrict public access to the buckets.

The most critical immediate action for publicly accessible sensitive S3 buckets is to restrict public access. This directly mitigates the data breach risk by preventing unauthorized external users from accessing the data.

Why the other options are wrong

  • A. Cross-region replication provides data redundancy but doesn't secure publicly exposed data.
  • B. Versioning helps with data recovery but doesn't address unauthorized public access.
  • C. Server-side encryption protects data at rest but doesn't prevent public access if the bucket policy allows it.

S3 Public Access Best Practice

A fundamental security best practice for Amazon S3 (and similar object storage services) is to block all public access to buckets, especially those containing sensitive data, unless explicitly required and carefully controlled.

  • Default S3 buckets are private
  • Public access can be granted via bucket policies or ACLs
  • Tools like S3 Block Public Access can enforce this organization-wide

Memory trick: S3: Secure Storage, Block Public Paths.

More Cloud Security questions