AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard

A security engineer needs to configure an S3 bucket policy for a new data lake. The policy must ensure that all objects uploaded to the bucket are encrypted using server-side encryption with AWS Key Management Service (SSE-KMS) and that the specific KMS key 'arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567' is used. Furthermore, any upload request that does not specify this encryption method and key must be explicitly denied. Which S3 bucket policy statement achieves this requirement?

  1. A{ "Version": "2012-10-17", "Statement": [ { "Sid": "EnforceSpecificKMS", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" }, "Null": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "false" }, "StringNotEqualsIfExists": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }
  2. B{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyUnencryptedUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "Null": { "s3:x-amz-server-side-encryption": "true" } } } ] }
  3. C{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyNonKMSUploads", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" } } } ] }
  4. D{ "Version": "2012-10-17", "Statement": [ { "Sid": "DenyWrongKMSKey", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }
Show answer & explanation

Correct answer: A. { "Version": "2012-10-17", "Statement": [ { "Sid": "EnforceSpecificKMS", "Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::my-data-lake-bucket/*", "Condition": { "StringNotEquals": { "s3:x-amz-server-side-encryption": "aws:kms" }, "Null": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "false" }, "StringNotEqualsIfExists": { "s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abcde123-4567-8901-2345-678901234567" } } } ] }

This policy statement correctly combines multiple conditions to explicitly deny `PutObject` requests that do not specify SSE-KMS, do not specify a KMS key, or specify a KMS key different from the required ARN. The `StringNotEquals` condition checks the encryption type, `Null` ensures a KMS key ID is provided, and `StringNotEqualsIfExists` enforces the specific KMS key ARN.

Why the other options are wrong

  • B. This only denies uploads if the `x-amz-server-side-encryption` header is completely `Null`, not if it's present but not 'aws:kms' or if the wrong key is used.
  • C. This denies uploads only if the encryption is not 'aws:kms'. It doesn't enforce that a specific KMS key is used or that a KMS key ID is even provided.
  • D. This denies uploads only if the KMS key ID does not match the specified ARN. It does not enforce that SSE-KMS is used, nor does it deny if no KMS key ID is provided at all.

S3 Bucket Policy for SSE-KMS Enforcement

A bucket policy using conditions to enforce server-side encryption with a specific AWS KMS key for all uploaded objects.

  • Uses `s3:x-amz-server-side-encryption` condition key to check encryption type.
  • Uses `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key to check the KMS key ARN.
  • Combines `StringNotEquals`, `Null`, and `StringNotEqualsIfExists` to ensure comprehensive enforcement.

Memory trick: Think of a 'triple-check' at the S3 upload gate: Is it KMS? Is there a key ID? Is it THE specific key?

More Domain 4: Identity and Access Management questions