A security administrator is reviewing an Amazon S3 bucket policy. The policy allows `s3:PutObject` action from a specific VPC endpoint (`vpce-1234567890abcdef0`) but implicitly denies all other principals. The administrator wants to ensure that all objects uploaded to this bucket are encrypted at rest using server-side encryption with AWS Key Management Service (SSE-KMS), and that only a specific KMS key (`arn:aws:kms:us-east-1:123456789012:key/abc-123`) is used. How should the S3 bucket policy be modified to enforce this encryption requirement?
- AAdd a condition `"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms", "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc-123"}` to the existing `s3:PutObject` statement.
- BAdd a condition `"StringNotEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc-123"}` with an `Effect: "Deny"`.
- CEnable default encryption for the S3 bucket using SSE-S3 and rely on client-side encryption for KMS.
- DAdd a condition `"StringEquals": {"s3:x-amz-server-side-encryption": "AES256"}` to the existing `s3:PutObject` statement.
Show answer & explanationAnswer & explanation
Correct answer: A. Add a condition `"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms", "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc-123"}` to the existing `s3:PutObject` statement.
To enforce SSE-KMS with a specific KMS key in a bucket policy, you must use two condition keys: `s3:x-amz-server-side-encryption` to ensure it's KMS encryption, and `s3:x-amz-server-side-encryption-aws-kms-key-id` to specify the exact KMS key ARN. Both conditions should be `StringEquals` within an `Allow` statement or `StringNotEquals` with a `Deny` statement for objects not using the required encryption.
Why the other options are wrong
- B. This condition, if used with a `Deny` effect, would deny if the specified key *is not* used, which is a valid approach for enforcement, but the prompt asks for modification to the *existing allow* statement to *enforce* (implying allow only if) the encryption. The `StringNotEquals` with Deny could be used, but `StringEquals` with Allow is more direct for positive enforcement.
- C. Enabling default encryption with SSE-S3 does not enforce SSE-KMS, nor does it allow specifying a particular KMS key. Client-side encryption is managed by the client, not enforced by the bucket policy.
- D. This condition enforces AES256 (SSE-S3), not SSE-KMS with a specific KMS key. It's incorrect for the requirement.
S3 Bucket Policy for Encryption Enforcement
S3 bucket policies can use condition keys to enforce server-side encryption requirements, such as mandating SSE-KMS with a specific KMS key for uploaded objects.
- Uses `s3:x-amz-server-side-encryption` for encryption type.
- Uses `s3:x-amz-server-side-encryption-aws-kms-key-id` for specific KMS key.
- Can be used with `Allow` or `Deny` effects.
Memory trick: S3 Policy ensures KMS key is used for encryption.