AWS Certified Security – SpecialtyDomain 4: Identity and Access ManagementHard

A company uses AWS Organizations and has several member accounts. They want to ensure that specific sensitive S3 buckets, located in a 'DataLake' member account, can only be accessed by IAM roles within that same 'DataLake' account and by a dedicated 'AnalyticsRole' in a separate 'Analytics' member account. All other cross-account access to these buckets, including by the root user of any member account, must be explicitly denied. How can this be achieved most securely and efficiently?

  1. AApply a bucket policy to each sensitive S3 bucket that explicitly denies access to all principals except the specified roles and accounts.
  2. BImplement a combination of S3 bucket policies and an SCP to deny `s3:*` actions from principals outside the allowed accounts, including the root user.
  3. CUse an AWS Organizations Service Control Policy (SCP) to deny the `s3:GetObject` and `s3:PutObject` actions for all principals in all accounts, except for the 'DataLake' and 'Analytics' accounts.
  4. DConfigure an IAM permission boundary for all IAM roles in all accounts, restricting their ability to access the sensitive S3 buckets.
Show answer & explanation

Correct answer: B. Implement a combination of S3 bucket policies and an SCP to deny `s3:*` actions from principals outside the allowed accounts, including the root user.

A combination of S3 bucket policies and an SCP is the most secure and efficient. The S3 bucket policy allows specific access from the 'AnalyticsRole' and within the 'DataLake' account. The SCP, applied at the Organization Unit (OU) level containing the DataLake and Analytics accounts, can explicitly deny `s3:*` actions to any principal (including root users) originating from accounts outside the allowed list, acting as a guardrail that prevents even administrators from circumventing the bucket policy.

Why the other options are wrong

  • A. A bucket policy alone cannot restrict the root user of other accounts, as root users bypass IAM policies (though not SCPs).
  • C. An SCP alone cannot grant specific access based on roles within accounts; it primarily defines maximum permissions or denies actions.
  • D. IAM permission boundaries set maximum permissions for IAM entities within an account, but don't prevent cross-account access by other root users or provide centralized organizational control.

S3 Bucket Policies & SCPs for Cross-Account Access

Combining S3 bucket policies for granular resource-based access with Service Control Policies (SCPs) for organizational-level guardrails, including root user restrictions.

  • S3 bucket policies define who can access the bucket and from where.
  • SCPs set maximum permissions for all IAM entities (including root users) within accounts in an AWS Organization.
  • Using both provides defense-in-depth: bucket policies manage allowed access, SCPs prevent disallowed access from other accounts, especially root.

Memory trick: Think of a 'double lock': the bucket policy is the inner lock, and the SCP is the outer gate for the whole organization.

More Domain 4: Identity and Access Management questions