Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Security Posture Management (CSPM)Medium

A security analyst is investigating a high-severity alert in Prisma Cloud indicating 'Publicly Exposed S3 Bucket' for an S3 bucket named 'my-company-data'. Upon inspection, the bucket policy explicitly denies public access, but the alert persists. Which of the following is the MOST likely reason for the continued alert, assuming no other bucket policy changes?

  1. AAn AWS CloudFront distribution is configured to serve content from the bucket publicly.
  2. BThe S3 bucket has cross-region replication enabled, exposing a replica.
  3. CPrisma Cloud's scan interval has not yet re-evaluated the bucket's status.
  4. DThe bucket has an Access Control List (ACL) granting public read access.
Show answer & explanation

Correct answer: D. The bucket has an Access Control List (ACL) granting public read access.

While bucket policies can deny public access, S3 ACLs operate independently and can override or coexist with bucket policies to grant public access. If an ACL grants public read access, the bucket will still be considered publicly exposed despite a restrictive bucket policy.

Why the other options are wrong

  • A. A CloudFront distribution can serve content publicly, but it doesn't make the S3 bucket itself directly publicly exposed in the same way an ACL or bucket policy does for direct S3 access.
  • B. Cross-region replication itself doesn't inherently expose a bucket; the replica would also need public access configured.
  • C. While scan intervals can cause temporary delays, a persistent alert suggests an underlying configuration issue, not just a timing lag.

S3 Public Exposure Vectors

Mechanisms through which an Amazon S3 bucket can become publicly accessible, often involving bucket policies, ACLs, or Block Public Access settings.

  • S3 Bucket Policies define access rules at the bucket level.
  • S3 Access Control Lists (ACLs) grant object-level and bucket-level permissions.
  • AWS S3 Block Public Access settings provide a crucial layer to prevent public exposure.

Memory trick: Don't just check the bucket policy, remember the ACLs and block public access too!

More Cloud Security Posture Management (CSPM) questions