A company is implementing a new policy that requires all S3 buckets to be encrypted at rest. They want to enforce this at the account level to prevent any unencrypted objects from being uploaded to any S3 bucket. If an object is uploaded without encryption headers, it should be denied. Which S3 bucket policy should be implemented to meet this requirement?
- A```json { "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedObjectUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*", "Condition": { "Null": { "s3:x-amz-server-side-encryption": "true" } } } ] } ```
- B```json { "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedObjectUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*", "Condition": { "ForAllValues:StringNotLike": { "s3:x-amz-server-side-encryption": [ "AES256", "aws:kms" ] } } } ] } ```
- C```json { "Version": "2012-10-17", "Statement": [ { "Sid": "RequireEncryption", "Effect": "Allow", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*", "Condition": { "Bool": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "true" } } } ] } ```
- D```json { "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedObjectUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": [ "AES256", "aws:kms" ] } } } ] } ```
Show answer & explanationAnswer & explanation
Correct answer: A. ```json { "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedObjectUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::DOC-EXAMPLE-BUCKET/*", "Condition": { "Null": { "s3:x-amz-server-side-encryption": "true" } } } ] } ```
To deny uploads of unencrypted objects, the policy needs to explicitly deny `s3:PutObject` if the relevant encryption header is *not* present. The `Null` condition operator with `"s3:x-amz-server-side-encryption": "true"` effectively checks if the `x-amz-server-side-encryption` header (or related KMS headers like `x-amz-server-side-encryption-aws-kms-key-id`) is *not* provided in the request. If this header is null (i.e., not present), the condition evaluates to true, and the upload is denied.
Why the other options are wrong
- B. `ForAllValues:StringNotLike` is used for multi-valued context keys and lists, which is not applicable here for a single header. The logic for denying based on a missing header is best handled by the `Null` condition.
- C. This is an `Allow` statement, which means it would only allow uploads *if* `s3:x-amz-server-side-encryption-aws-kms-key-id` is present. If it's not present, the request would be implicitly denied, but this is less explicit and might not catch other unencrypted scenarios. Also, `Bool` is not the correct operator for this condition key.
- D. This policy uses `StringNotEquals` to deny if the encryption header is *not* AES256 or aws:kms. This would deny uploads that use, for example, SSE-C or if the header is missing entirely. However, the most direct way to deny if *no* encryption header is present is using the `Null` condition for the header itself.
S3 Bucket Policy for Encryption Enforcement
An S3 bucket policy using conditions to deny `s3:PutObject` actions if specific server-side encryption headers are not present in the request.
- Uses `Effect: Deny` for `s3:PutObject` action.
- Condition `Null` with `"s3:x-amz-server-side-encryption": "true"` denies if encryption header is missing.
- Alternatively, `StringNotEquals` can deny if a specific encryption type is not used.
- Enforces encryption at rest for all new objects uploaded to the bucket.
Memory trick: Deny null encryption, for data's protection.