A security engineer needs to configure an S3 bucket policy for a new data lake. The policy must ensure that all objects uploaded to the bucket are encrypted using server-side encryption with AWS Key Management Service (SSE-KMS) and that the specific KMS key 'arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567' is used. Furthermore, any upload request that does not specify this encryption method and key must be explicitly denied. Which S3 bucket policy statement achieves this requirement?
- A{ "Version": "2012-10-17", "Statement": [ { "Sid": "EnforceSpecificKMS", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" }, "Null": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "false" }, "StringNotEqualsIfExists": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }
- B{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "Null": { "s3:x-amz-server-side-encryption": "true" } } } ] }
- C{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyNonKMSUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" } } } ] }
- D{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyWrongKMSKey", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }
Show answer & explanationAnswer & explanation
Correct answer: A. { "Version": "2012-10-17", "Statement": [ { "Sid": "EnforceSpecificKMS", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" }, "Null": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "false" }, "StringNotEqualsIfExists": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }
This policy statement correctly combines multiple conditions to explicitly deny `PutObject` requests that do not specify SSE-KMS, do not specify a KMS key, or specify a KMS key different from the required ARN. The `StringNotEquals` condition checks the encryption type, `Null` ensures a KMS key ID is provided, and `StringNotEqualsIfExists` enforces the specific KMS key ARN.
Why the other options are wrong
- B. This only denies uploads if the `x-amz-server-side-encryption` header is completely `Null`, not if it's present but not 'aws:kms' or if the wrong key is used.
- C. This denies uploads only if the encryption is not 'aws:kms'. It doesn't enforce that a specific KMS key is used or that a KMS key ID is even provided.
- D. This denies uploads only if the KMS key ID does not match the specified ARN. It does not enforce that SSE-KMS is used, nor does it deny if no KMS key ID is provided at all.
S3 Bucket Policy for SSE-KMS Enforcement
A bucket policy using conditions to enforce server-side encryption with a specific AWS KMS key for all uploaded objects.
- Uses `s3:x-amz-server-side-encryption` condition key to check encryption type.
- Uses `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key to check the KMS key ARN.
- Combines `StringNotEquals`, `Null`, and `StringNotEqualsIfExists` to ensure comprehensive enforcement.
Memory trick: Think of a 'triple-check' at the S3 upload gate: Is it KMS? Is there a key ID? Is it THE specific key?