AWS Certified Security – SpecialtyDomain 3: Infrastructure SecurityMedium

A healthcare organization stores sensitive patient data in an Amazon S3 bucket. They need to ensure that all data uploaded to this bucket is encrypted at rest and that only authorized users within their AWS account can access it. Additionally, they must prevent accidental public exposure of the bucket. Which combination of S3 features will best meet these security requirements?

  1. AApply a bucket policy to restrict access to specific IAM roles and use client-side encryption for all uploads.
  2. BEnable default encryption for the S3 bucket using SSE-KMS and enable Block Public Access settings for the bucket.
  3. CEnable default encryption for the S3 bucket using SSE-S3 and apply a bucket policy that denies public access.
  4. DConfigure S3 Access Points with specific IAM policies and enable versioning on the bucket.
Show answer & explanation

Correct answer: B. Enable default encryption for the S3 bucket using SSE-KMS and enable Block Public Access settings for the bucket.

SSE-KMS provides server-side encryption with AWS Key Management Service, offering an audit trail for key usage, which is often a requirement for sensitive data. Block Public Access settings are crucial for preventing accidental public exposure of S3 buckets.

Why the other options are wrong

  • A. Client-side encryption requires application changes and doesn't enforce encryption at the bucket level for all uploads. IAM policies restrict access, but don't prevent public exposure as effectively as Block Public Access.
  • C. SSE-S3 is an option, but SSE-KMS offers more control and auditing. Denying public access via bucket policy is less comprehensive than Block Public Access.
  • D. S3 Access Points simplify access management for specific applications, but don't directly enforce encryption or prevent public access. Versioning protects against accidental deletions but not public exposure or encryption at rest.

S3 Data Protection Best Practices

A combination of S3 features like encryption, access control, and public access blocking is essential for securing sensitive data in S3.

  • Default encryption ensures all new objects are encrypted.
  • Block Public Access prevents accidental public exposure.
  • IAM policies and bucket policies control authorized access.

Memory trick: Encrypt, Block, and Control for S3 Data Security.

More Domain 3: Infrastructure Security questions