Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityHard

A security auditor is reviewing a company's cloud infrastructure and notices that several Amazon S3 buckets storing sensitive customer data are publicly accessible. This violates data privacy regulations and internal security policies. What is the most immediate and critical best practice to apply to mitigate this risk?

  1. AImplement server-side encryption for all objects in the S3 buckets.
  2. BRestrict public access to the S3 buckets using bucket policies or Block Public Access settings.
  3. CConfigure AWS CloudTrail to log all S3 data events for forensic analysis.
  4. DEnable versioning on all S3 buckets to prevent accidental deletion.
Show answer & explanation

Correct answer: B. Restrict public access to the S3 buckets using bucket policies or Block Public Access settings.

The most immediate and critical step to mitigate publicly accessible sensitive data is to restrict that public access. AWS offers 'Block Public Access' settings at the account or bucket level, and granular bucket policies, which are specifically designed to prevent unintended public exposure of S3 content.

Why the other options are wrong

  • A. Encryption protects data at rest but does not prevent an unauthorized public user from accessing and decrypting publicly available encrypted data.
  • C. CloudTrail logs actions for auditing, but it does not prevent the public exposure itself.
  • D. Versioning helps with data recovery but does not prevent public access to sensitive data.

S3 Public Access Best Practice

By default, S3 buckets are private. Preventing accidental or intentional public access to sensitive data in S3 is a critical cloud security best practice, typically achieved through Block Public Access settings and restrictive bucket policies.

  • S3 buckets are private by default.
  • Public access should be explicitly blocked for sensitive data.
  • AWS provides 'Block Public Access' settings and bucket policies for control.

Memory trick: For S3, 'B'lock 'P'ublic 'A'ccess before data 'L'eaks.

More Cloud Security questions