AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceMedium
A DevOps engineer is configuring an Amazon S3 bucket to store sensitive audit logs. The security team has mandated that the logs must be encrypted at rest, and access to the bucket must be restricted to specific IAM roles only. Additionally, the bucket must prevent accidental deletion of objects and previous versions. Which combination of S3 features should the engineer enable to meet these requirements?
- ADefault Encryption with SSE-C, IAM Policies, and S3 Replication.
- BClient-Side Encryption, Access Control Lists (ACLs), and S3 Object Lock.
- CServer-Side Encryption with S3-managed keys (SSE-S3), Bucket Policies, and S3 Lifecycle Policies.
- DServer-Side Encryption with KMS keys (SSE-KMS), Bucket Policies, and S3 Versioning with MFA Delete.
Show answer & explanationAnswer & explanation
Correct answer: D. Server-Side Encryption with KMS keys (SSE-KMS), Bucket Policies, and S3 Versioning with MFA Delete.
SSE-KMS encrypts objects with KMS keys, providing better control and auditability than SSE-S3. Bucket Policies restrict access to specific IAM roles. S3 Versioning protects against accidental deletion by keeping old versions, and MFA Delete adds an extra layer of protection requiring multi-factor authentication for versioned object deletions.
Why the other options are wrong
- A. SSE-C requires the client to manage keys. IAM policies are part of access control but usually combined with bucket policies. S3 Replication is for disaster recovery, not accidental deletion prevention of the source objects.
- B. Client-Side Encryption shifts encryption responsibility to the client. ACLs are less flexible than Bucket Policies for role-based access. S3 Object Lock provides WORM, but MFA Delete on versioning is specifically for accidental deletion protection of versions.
- C. SSE-S3 is encryption but SSE-KMS offers more control. Lifecycle policies manage object transitions/expiration, not protection against accidental deletion of current versions, and MFA Delete is missing.
S3 Security Best Practices
A set of guidelines and configurations for Amazon S3 buckets to protect data at rest, control access, and ensure data durability and integrity.
- Encryption at rest (SSE-KMS preferred).
- Least privilege access control (Bucket Policies, IAM).
- Protection against accidental deletion (Versioning, MFA Delete, Object Lock).
Memory trick: KMS encrypts, Policies restrict, Versioning + MFA protects from delete.