AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium
A security auditor requires proof that all Amazon S3 buckets containing sensitive customer data are protected against accidental deletion or modification for a minimum of one year. The auditor needs to verify that this protection is active and cannot be easily bypassed. Which S3 feature should be enabled and how can its enforcement be demonstrated?
- AApply a bucket policy that denies 's3:DeleteObject' and 's3:PutObject' for all users except a break-glass role, and show the policy.
- BEnable S3 Versioning on the buckets and prove it by showing multiple versions of objects.
- CEnable S3 Object Lock in Compliance mode with a retention period of one year on the buckets, and demonstrate by attempting to delete a locked object.
- DEnable S3 Block Public Access at the account level and show that the buckets are not publicly accessible.
Show answer & explanationAnswer & explanation
Correct answer: C. Enable S3 Object Lock in Compliance mode with a retention period of one year on the buckets, and demonstrate by attempting to delete a locked object.
S3 Object Lock in Compliance mode prevents an object from being overwritten or deleted by any user, including the root user, during the specified retention period, thus meeting the requirement for protection against accidental deletion or modification and providing strong evidence to an auditor.
Why the other options are wrong
- A. A bucket policy can be modified or removed by an authorized user, including the root user, and therefore doesn't provide the immutable protection required by an auditor.
- B. S3 Versioning allows recovery from accidental deletion/overwriting but doesn't prevent deletion of all versions or the bucket itself, and it can be suspended.
- D. S3 Block Public Access prevents public access but does not protect against accidental deletion or modification by authenticated users, which is the core requirement.
S3 Object Lock (Compliance Mode)
An S3 feature that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, with Compliance mode being the most stringent.
- Provides WORM (Write Once, Read Many) protection
- Compliance mode prevents deletion even by root user
- Crucial for regulatory compliance and data immutability
Memory trick: Lock it down, auditor will frown if it's not sound.