Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cloud SecurityMedium

A security auditor is reviewing a company's cloud infrastructure and discovers several S3 buckets configured with public read/write access. These buckets contain sensitive customer data. Which cloud security best practice has been violated, and what is the immediate risk?

  1. AViolation of secure identity management, immediate risk of credential theft.
  2. BViolation of secure data at rest, immediate risk of data loss due to malicious deletion.
  3. CViolation of the principle of least privilege, immediate risk of unauthorized network access.
  4. DViolation of S3 public access best practices, immediate risk of data exposure and integrity compromise.
Show answer & explanation

Correct answer: D. Violation of S3 public access best practices, immediate risk of data exposure and integrity compromise.

Public read/write access on S3 buckets containing sensitive data directly violates the best practice of restricting public access to sensitive cloud storage. The immediate risk is unauthorized parties reading the sensitive data (exposure) and potentially modifying or deleting it (integrity compromise).

Why the other options are wrong

  • A. Identity management is about user/service access. Public access applies to anyone, bypassing typical identity management controls.
  • B. This touches on data loss, but 'secure data at rest' is broader; the specific violation is public access, and the risk includes exposure and integrity, not just loss.
  • C. While least privilege is related, the direct violation is public access, and the risk is data exposure, not just network access.

S3 Public Access Best Practice

The security best practice of blocking public access to Amazon S3 buckets, especially those containing sensitive data, to prevent unauthorized data exposure and modification.

  • Default S3 settings should block public access
  • Use bucket policies and ACLs to restrict access
  • Regularly audit S3 bucket configurations

Memory trick: Don't leave your S3 bucket door wide open!

More Cloud Security questions