AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium
A security audit has identified that several Amazon S3 buckets containing sensitive customer data are publicly accessible. The security team needs to implement an automated solution to prevent new public S3 buckets from being created and to automatically remediate existing public buckets by blocking public access. Which combination of AWS services should be used?
- AAmazon Macie for detection and AWS Step Functions for remediation.
- BAWS CloudTrail for logging and Amazon EventBridge for alerts.
- CAWS Config rules for detection and AWS Lambda for remediation.
- DAWS Organizations Service Control Policies (SCPs) and Amazon S3 Block Public Access.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Organizations Service Control Policies (SCPs) and Amazon S3 Block Public Access.
AWS Organizations SCPs can prevent the creation of public S3 buckets across an organization, enforcing preventative controls. Amazon S3 Block Public Access is a native S3 feature that can be applied at the account or bucket level to block public access, effectively remediating existing public buckets and preventing future misconfigurations.
Why the other options are wrong
- A. Macie detects sensitive data, not necessarily public access, and Step Functions are for workflow orchestration, not direct remediation of S3 public access.
- B. CloudTrail logs actions and EventBridge can trigger alerts, but neither directly prevents or remediates public access in a comprehensive, automated way.
- C. AWS Config can detect non-compliance, and Lambda can remediate, but SCPs provide a stronger preventative control at the organizational level.
S3 Public Access Prevention
Preventing public access to Amazon S3 buckets is crucial for data security and compliance, often achieved through a combination of preventative and detective controls.
- Amazon S3 Block Public Access settings are the primary control.
- AWS Organizations SCPs can prevent public access at the organizational level.
- AWS Config can detect and remediate non-compliant buckets.
Memory trick: SCP Stops Public S3, Block Public Access Locks It Down.