AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a mobile application that needs to retrieve images stored in an Amazon S3 bucket. The images are highly sensitive and should only be accessible for a limited time after a user requests them. The application should not expose AWS credentials to the mobile client. Which is the most secure way to grant temporary access to these S3 objects?

  1. AUse an IAM role with S3 read permissions assigned to the mobile application.
  2. BGenerate pre-signed URLs for the S3 objects from a backend service.
  3. CMake the S3 bucket public and restrict access using a bucket policy based on IP.
  4. DStore AWS credentials directly in the mobile application to access S3.
Show answer & explanation

Correct answer: B. Generate pre-signed URLs for the S3 objects from a backend service.

Generating pre-signed URLs from a backend service is the most secure and recommended approach. The backend service (e.g., a Lambda function or EC2 instance) with appropriate S3 permissions generates a time-limited URL. The mobile client then uses this URL to access the object directly from S3 without ever needing AWS credentials, ensuring temporary and secure access.

Why the other options are wrong

  • A. Assigning an IAM role directly to a mobile application is not a standard or secure practice, as mobile clients should not hold long-lived AWS credentials.
  • C. Making an S3 bucket public is a significant security risk and does not provide temporary access or protect sensitive data adequately.
  • D. Storing AWS credentials directly in a mobile application is highly insecure and a major security vulnerability.

S3 Pre-Signed URLs

A URL that grants temporary access to a specific S3 object. It is generated by an authorized AWS user or application and contains security credentials that are valid for a specified duration.

  • Provides temporary access to S3 objects
  • Does not expose AWS credentials to the client
  • Generated by an authorized backend service

Memory trick: The mobile gets a 'ticket' (pre-signed URL) to the S3 bucket.

More Security questions