A highly regulated enterprise manages multiple AWS accounts and needs to enforce a strict policy that prevents the creation of public S3 buckets across all accounts, without exception. Any attempt to create a public S3 bucket must be denied at the API level. Which AWS service should the DevOps team use to implement this preventative control?
- AAWS Config rules with auto-remediation.
- BService Control Policies (SCPs) in AWS Organizations.
- CAWS WAF rules applied to S3 buckets.
- DS3 bucket policies configured on each individual bucket.
Show answer & explanationAnswer & explanation
Correct answer: B. Service Control Policies (SCPs) in AWS Organizations.
Service Control Policies (SCPs) in AWS Organizations are used to manage permissions in the organization. They offer a powerful way to centrally control the maximum available permissions for all accounts in an organization. By denying the `s3:PutBucketPolicy` or `s3:PutBucketPublicAccessBlock` actions that allow public access, SCPs act as a guardrail, preventing any account from making S3 buckets public, even if an IAM policy would otherwise permit it. SCPs are preventative controls, denying actions at the API level.
Why the other options are wrong
- A. AWS Config rules are detective and corrective; they identify non-compliant resources *after* they are created and then remediate. The requirement is to *prevent* creation at the API level.
- C. AWS WAF protects against web exploits but does not control S3 bucket creation or public access settings at the API level.
- D. S3 bucket policies are configured on individual buckets, which doesn't provide a centralized, preventative control across all accounts and can be overridden or misconfigured.
AWS Organizations Service Control Policies (SCPs)
SCPs are policy-based controls that specify the maximum permissions for an organization's accounts. They act as guardrails to ensure accounts stay within your organization's access control guidelines.
- Preventative controls, deny actions at the API level.
- Apply across multiple AWS accounts in an Organization.
- Cannot grant permissions, only restrict them.
Memory trick: SCPs are the ultimate gate, no public S3, it seals the fate, across all accounts, it sets the state.