AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium

A healthcare provider is moving its sensitive patient data to Amazon S3. Compliance regulations mandate that all stored data must be encrypted at rest. Furthermore, access to this data must be strictly controlled, with different departments having varying levels of access. The security team wants to ensure that S3 bucket policies are not overly permissive and that access is granted based on the principle of least privilege. Which combination of AWS services and features should be used to enforce these access controls and compliance for the S3 buckets?

  1. AS3 Bucket Policies, IAM Policies, and S3 Block Public Access
  2. BAWS Organizations, Service Control Policies (SCPs), and AWS Config
  3. CAmazon GuardDuty, AWS Shield, and AWS KMS
  4. DNetwork ACLs, Security Groups, and AWS WAF
Show answer & explanation

Correct answer: A. S3 Bucket Policies, IAM Policies, and S3 Block Public Access

S3 Bucket Policies and IAM Policies are fundamental for controlling access to S3 buckets and objects. S3 Block Public Access is a critical feature to prevent accidental public exposure of data, addressing the concern about overly permissive policies. While encryption at rest is also a requirement, these services directly address the access control and policy enforcement aspects for S3 buckets.

Why the other options are wrong

  • B. AWS Organizations and SCPs enforce guardrails at the account level, while AWS Config monitors compliance; these are higher-level tools, not the direct mechanisms for S3 bucket access control.
  • C. Amazon GuardDuty detects threats, AWS Shield provides DDoS protection, and AWS KMS manages encryption keys; these do not directly manage S3 bucket access policies.
  • D. Network ACLs and Security Groups control network traffic to EC2 instances/VPCs, not direct access to S3 buckets. AWS WAF protects web applications.

S3 Access Control

Mechanisms used to define who can access Amazon S3 buckets and objects, and what actions they can perform.

  • IAM Policies: Identity-based access control.
  • S3 Bucket Policies: Resource-based access control.
  • S3 Block Public Access: Prevents public access at account/bucket level.

Memory trick: IAM controls 'WHO', Bucket 'WHAT', Block 'NO PUBLIC'.

More Network Security, Compliance, and Governance questions