AWS Certified SysOps Administrator – AssociateSecurity and ComplianceMedium

A company needs to restrict access to an S3 bucket containing sensitive organizational documents. Only users from specific IP ranges within the corporate network should be able to download objects from this bucket. Additionally, public access to the bucket must be explicitly denied. Which combination of S3 access controls should the SysOps administrator configure?

  1. AUse a VPC Endpoint policy to restrict access and configure S3 Cross-Origin Resource Sharing (CORS).
  2. BUse S3 ACLs to deny public access and configure IAM user policies with IP conditions.
  3. CApply a bucket policy to restrict access by IP address and enable S3 Block Public Access settings.
  4. DImplement S3 Object ACLs for specific IP restrictions and enable S3 versioning.
Show answer & explanation

Correct answer: C. Apply a bucket policy to restrict access by IP address and enable S3 Block Public Access settings.

An S3 bucket policy is the most effective way to define permissions at the bucket level, including restricting access based on source IP addresses using a `Condition` block with `aws:SourceIp`. S3 Block Public Access settings provide a strong, account-level or bucket-level control to ensure that no object or bucket can be made public, regardless of individual permissions or future configurations, directly addressing the requirement to explicitly deny public access.

Why the other options are wrong

  • A. VPC Endpoint policies restrict access to S3 from within a VPC, but the question implies access from a corporate network which may or may not be directly connected via VPC endpoint. CORS is for browser-based cross-domain requests, not for IP-based access restrictions or public access denial.
  • B. While S3 ACLs can manage public access, S3 Block Public Access is a more comprehensive and recommended control for denying all public access. IAM user policies are for individual users, whereas a bucket policy is more suitable for network-wide restrictions.
  • D. S3 Object ACLs apply to individual objects, not the entire bucket, making them less efficient for a blanket IP restriction. S3 versioning is for data protection, not access control.

S3 Access Control Best Practices

Combine S3 bucket policies for fine-grained permissions and S3 Block Public Access settings to prevent unintended public exposure of sensitive data.

  • Bucket policies control access at the bucket level.
  • Bucket policies support IP conditions.
  • S3 Block Public Access prevents all public access.
  • Block Public Access is a strong preventative control.

Memory trick: Bucket Policy is the bouncer, Block Public Access is the bolted door.

More Security and Compliance questions