A security auditor has identified that several Amazon S3 buckets containing sensitive customer data are publicly accessible. The company needs to implement a preventative measure to ensure that no S3 bucket can ever be made publicly accessible, regardless of individual bucket policies or ACLs, across all AWS accounts in their organization. Which solution would achieve this MOST effectively?
- AEnable S3 Block Public Access settings for each individual S3 bucket.
- BCreate an AWS Organizations Service Control Policy (SCP) to deny `s3:PutBucketPolicy` and `s3:PutBucketAcl` actions if they would grant public access.
- CImplement an AWS Config rule to detect public S3 buckets and automatically remediate them.
- DApply S3 Block Public Access settings at the AWS account level for all accounts.
Show answer & explanationAnswer & explanation
Correct answer: D. Apply S3 Block Public Access settings at the AWS account level for all accounts.
S3 Block Public Access settings at the account level are the most effective and comprehensive way to prevent public access to S3 buckets. These settings override individual bucket policies and ACLs, ensuring no bucket can be made public within that account. Applying this across all accounts ensures organizational compliance.
Why the other options are wrong
- A. Enabling S3 Block Public Access on individual buckets is effective but requires manual action per bucket and might be missed for new buckets, lacking organization-wide enforcement.
- B. While an SCP could deny `s3:PutBucketPolicy` and `s3:PutBucketAcl` actions that grant public access, the S3 Block Public Access settings at the account level are a more direct, comprehensive, and purpose-built preventative control for this specific problem, overriding all public access mechanisms without needing to parse policy content in an SCP.
- C. AWS Config rules are reactive; they detect non-compliance after it occurs. While they can remediate, they don't prevent the initial public access, which is less ideal for a strict preventative requirement.
S3 Block Public Access (Account Level)
Amazon S3 Block Public Access provides settings to block public access to S3 buckets and objects at the account level or bucket level. When applied at the account level, these settings override any individual bucket or object settings, ensuring no S3 resources within that account can be publicly accessible.
- Prevents public access to S3 buckets and objects.
- Can be applied at account or bucket level.
- Account-level settings override all other settings.
- Four specific settings to block public access.
Memory trick: Account-level Block Public Access: The Ultimate S3 Guard.