AWS Certified Developer – Associate (DVA-C02)SecurityEasy

A developer is building a new application that will use Amazon S3 to store publicly accessible static website content, such as HTML, CSS, JavaScript, and images. While the content itself should be publicly readable, the S3 bucket should prevent unauthorized users from performing actions like deleting objects or modifying bucket configurations. Which S3 access control mechanism is MOST appropriate for this scenario?

  1. ABucket policy to grant public read access and restrict write/delete actions.
  2. BIAM user policies configured for specific public read access.
  3. CS3 Block Public Access settings at the account level.
  4. DObject ACLs to grant public read access to specific objects.
Show answer & explanation

Correct answer: A. Bucket policy to grant public read access and restrict write/delete actions.

A bucket policy is the most effective way to grant public read access to an entire bucket while explicitly denying write and delete actions for unauthorized users. It centrally manages permissions for the bucket and its objects.

Why the other options are wrong

  • B. IAM user policies are for specific users or roles within your AWS account, not for granting public access to anonymous users.
  • C. S3 Block Public Access settings are designed to prevent public access entirely, which contradicts the requirement for publicly accessible content.
  • D. Object ACLs are legacy and less flexible than bucket policies, and managing them for every object is cumbersome for a static website.

S3 Bucket Policy for Public Read, Restricted Write

An S3 bucket policy is an access policy language used to grant or deny permissions to specific AWS principals for a bucket and its objects. It's ideal for setting public read access while restricting administrative actions.

  • Centrally manages permissions for the entire bucket.
  • Can grant public read access (e.g., `s3:GetObject`).
  • Can explicitly deny write/delete actions for unauthorized users.

Memory trick: Bucket Policy Protects Public Content Prudently.

More Security questions