AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium
A financial institution uses AWS Organizations to manage multiple accounts. A security incident has been detected in a member account where an S3 bucket containing sensitive customer data was accidentally made public. The security team needs to quickly identify all other S3 buckets across all member accounts that might also be publicly accessible to prevent similar incidents and assess the full scope of the exposure. Which AWS service should they leverage for this task efficiently?
- AAWS Security Hub with the 'S3.3 S3 bucket policies should restrict public read access' control enabled.
- BAWS CloudTrail logs aggregated in a central S3 bucket.
- CAWS Config rules deployed across all accounts via AWS Organizations.
- DAmazon Macie findings aggregated to a central security account.
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Security Hub with the 'S3.3 S3 bucket policies should restrict public read access' control enabled.
AWS Security Hub, with its integrated controls like S3.3, provides a centralized view of security posture across all accounts, making it efficient for identifying publicly accessible S3 buckets and assessing the scope of exposure.
Why the other options are wrong
- B. CloudTrail logs record API calls but require complex parsing and analysis to identify public buckets, which is less efficient than Security Hub.
- C. AWS Config rules can identify public S3 buckets, but Security Hub aggregates these findings and provides a standardized, centralized view across accounts, which is more efficient for scope assessment.
- D. Amazon Macie focuses on sensitive data discovery and can identify public buckets, but Security Hub provides a broader, consolidated view of security findings from various services, including S3 public access, which is more direct for this specific scope assessment.
Centralized S3 Public Access Monitoring
Monitoring for publicly accessible S3 buckets across an AWS Organization is critical for data protection. AWS Security Hub offers a consolidated view of security findings, including S3 public access, making it effective for this task.
- Security Hub aggregates findings from various services.
- Pre-defined controls like S3.3 detect public S3 buckets.
- Provides a centralized dashboard for multi-account security posture.
Memory trick: Security Hub is the central security command center for all your AWS accounts.