A security engineer is designing an access strategy for a new application that will store highly sensitive customer data in an Amazon S3 bucket. Access to this bucket must be restricted to specific AWS IAM roles within the same AWS account and must also prevent data exfiltration by ensuring that objects can only be accessed from specific VPC endpoints. Additionally, the solution must prevent root user access to the bucket. Which combination of access control mechanisms should the security engineer implement to meet these requirements?
- AAttach an IAM policy to the S3 bucket that restricts access to the IAM roles and VPC endpoints. Use AWS Organizations Service Control Policies (SCPs) to deny root user access to S3.
- BImplement an IAM policy on the roles, an S3 ACL to restrict access to the VPC endpoints, and enable Block Public Access settings for S3 at the account level.
- CApply an S3 bucket policy that grants access only to the specified IAM roles, denies access if the request is not from the specified VPC endpoints, and explicitly denies access to the root user. Use IAM role policies to grant necessary permissions.
- DUse an IAM policy attached to the S3 bucket and a separate S3 bucket policy that denies access if the request is not from the specified VPC endpoints. Enable MFA Delete on the bucket.
Show answer & explanationAnswer & explanation
Correct answer: C. Apply an S3 bucket policy that grants access only to the specified IAM roles, denies access if the request is not from the specified VPC endpoints, and explicitly denies access to the root user. Use IAM role policies to grant necessary permissions.
An S3 bucket policy is the most effective way to enforce these granular, resource-based access controls directly on the bucket. It allows for specifying IAM roles, VPC endpoint conditions, and explicit denial for the root user. IAM role policies grant the necessary permissions to the roles themselves.
Why the other options are wrong
- A. IAM policies are attached to identities (users, roles), not directly to S3 buckets. While SCPs can restrict root user access for S3 actions across an organization, a bucket policy is more specific and directly enforces the access requirements on the bucket itself, including VPC endpoint and specific role conditions.
- B. S3 ACLs are an older access control mechanism and are not suitable for complex conditions like VPC endpoints or specific IAM roles. Account-level Block Public Access is good practice but doesn't address the specific IAM role or VPC endpoint requirements for this bucket, nor does it explicitly deny the root user.
- D. Attaching an IAM policy to the S3 bucket is not a standard S3 access control mechanism; IAM policies are attached to identities. MFA Delete is for object deletion, not general access control or root user restriction for the bucket.
S3 Bucket Policy
A resource-based access policy attached directly to an S3 bucket, allowing granular control over who can access the bucket and its objects, and under what conditions.
- Defines permissions at the bucket level.
- Can grant or deny access to IAM principals, AWS services, and external accounts.
- Supports conditions based on source IP, VPC endpoint, MFA status, and more.
Memory trick: Bucket Policies are the King, for all your S3 access string.