AWS Certified Machine Learning – SpecialtyData EngineeringMedium
A data engineer needs to ensure that sensitive customer data, stored in an Amazon S3 data lake, is only accessible by authorized machine learning models and specific data scientists. The data is encrypted at rest using KMS. To enforce fine-grained access control based on user roles and specific S3 prefixes (folders), which AWS service should be primarily used?
- AAWS Organizations
- BAWS WAF
- CAmazon S3 bucket policies
- DAmazon Cognito
Show answer & explanationAnswer & explanation
Correct answer: C. Amazon S3 bucket policies
Amazon S3 bucket policies are JSON-based policy documents that define permissions for access to S3 buckets and their objects. They allow fine-grained control, specifying who (IAM users/roles) can access which resources (S3 prefixes/objects) and what actions they can perform. This is the primary method for enforcing access control directly on S3 data.
Why the other options are wrong
- A. AWS Organizations helps you centrally manage and govern your environment as you grow and scale your AWS resources. While it manages accounts, it doesn't directly provide fine-grained access control to S3 objects.
- B. AWS WAF (Web Application Firewall) protects web applications from common web exploits. It's not used for controlling access to S3 objects based on IAM roles or S3 prefixes.
- D. Amazon Cognito provides user sign-up, sign-in, and access control for web and mobile apps. It manages user identities but relies on IAM roles and policies (including S3 bucket policies) to grant access to AWS resources.
Amazon S3 Bucket Policies
Resource-based access policies that grant or deny permissions for specific actions on an S3 bucket and its objects, directly attached to the S3 bucket itself.
- JSON-based policy language.
- Defines 'Principal', 'Action', 'Resource', and 'Effect'.
- Can grant cross-account access.
- Used for fine-grained access control at the bucket or object prefix level.
- Often used in conjunction with IAM user/role policies.
Memory trick: Bucket Policies are the bouncers for your S3 data, checking IDs.