AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A startup is developing a new social media application that needs to store large volumes of user-uploaded images and videos in Amazon S3. The application requires granular access control to these objects, where only the uploading user can access their own files, and administrators can access all files. The application backend runs on AWS Lambda. How can the developer implement this access control MOST effectively and securely?
- AUse S3 Access Control Lists (ACLs) to individually manage permissions for each object.
- BGenerate pre-signed URLs for users to upload and download their specific objects.
- CSet all S3 objects to public and rely on application-level authentication.
- DUse S3 bucket policies to grant access based on IAM user tags.
Show answer & explanationAnswer & explanation
Correct answer: B. Generate pre-signed URLs for users to upload and download their specific objects.
Pre-signed URLs are an effective way to grant temporary, time-limited access to specific S3 objects without exposing AWS credentials. The Lambda function can generate these URLs after authenticating the user, ensuring only authorized users can access their files.
Why the other options are wrong
- A. ACLs are an older S3 access control mechanism and become unmanageable at scale for millions of user-uploaded objects.
- C. Setting objects to public is a severe security risk and violates the requirement for granular access control.
- D. IAM user tags are not directly used by S3 bucket policies for per-object access control for individual users in a social media context.
S3 Pre-Signed URLs
S3 pre-signed URLs provide temporary security credentials to a user, allowing them to upload or download a specific object to/from an S3 bucket without requiring permanent AWS credentials or direct S3 permissions.
- Grants time-limited access (configurable expiry).
- Can be used for both uploads (PUT) and downloads (GET).
- Generated by an AWS SDK or CLI using valid AWS credentials.
Memory trick: Pre-signed links: a temporary key, just for you, just for this data.