Certified Cloud Security Professional (CCSP)Cloud Concepts, Architecture and DesignEasy
A cloud security team is implementing a strategy to protect sensitive data stored in an Amazon S3 bucket. They want to ensure that even if an attacker gains access to the S3 bucket, the data remains unreadable. Which security best practice should they prioritize?
- AImplementing strong access control lists (ACLs) on the bucket.
- BApplying strong encryption to the data at rest.
- CConfiguring public access blocks for the S3 bucket.
- DEnabling versioning for the S3 bucket.
Show answer & explanationAnswer & explanation
Correct answer: B. Applying strong encryption to the data at rest.
Applying strong encryption to data at rest ensures that even if an attacker gains unauthorized access to the storage location, the data itself is unreadable without the decryption key, thus achieving the goal.
Why the other options are wrong
- A. ACLs control access, but if bypassed, data is still readable.
- C. Public access blocks prevent public exposure, but don't protect data if a legitimate, but compromised, account accesses it.
- D. Versioning protects against accidental deletion or overwrites, not unauthorized reading of data.
Encryption at Rest
The practice of encrypting data when it is stored on a physical storage device, such as a hard drive, solid-state drive, or cloud storage bucket.
- Protects data from unauthorized access even if the storage medium is compromised.
- Can be managed by the customer (client-side) or the cloud provider (server-side).
- Crucial for data confidentiality and compliance requirements.
Memory trick: Encryption at rest is like locking your diary even if someone breaks into your room.