AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard
A global enterprise needs to securely share data with external partners. The data is stored in Amazon S3 buckets. The security team insists that data in transit must be encrypted at all times when partners access it. Additionally, access to the S3 buckets must be restricted to specific IP ranges belonging to the partners, and each partner should only be able to access their designated prefixes within the bucket. Which combination of S3 features and security mechanisms should be used?
- AUse IAM policies for partner access, enable S3 Object Lock, and allow both HTTP and HTTPS connections.
- BConfigure S3 bucket policies with 'aws:SourceIp' condition and 's3:prefix' conditions, and enforce HTTPS for all connections.
- CImplement S3 bucket policies with 'aws:SourceIp' condition, and enforce 's3:x-amz-server-side-encryption' for uploads.
- DUse S3 bucket policies with 'aws:SourceIp' condition, and ensure all partner connections use HTTP.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure S3 bucket policies with 'aws:SourceIp' condition and 's3:prefix' conditions, and enforce HTTPS for all connections.
Enforcing HTTPS for all connections ensures data is encrypted in transit. S3 bucket policies with the 'aws:SourceIp' condition restrict access to specific IP ranges. The 's3:prefix' condition in bucket policies allows granular control, ensuring partners only access their designated prefixes, meeting all requirements.
Why the other options are wrong
- A. IAM policies are for identity-based access, not IP range restriction. S3 Object Lock is for data immutability, not access control. Allowing HTTP violates the encryption in transit requirement.
- C. Enforcing server-side encryption (s3:x-amz-server-side-encryption) ensures data at rest is encrypted, but does not guarantee encryption in transit for downloads or uploads without HTTPS.
- D. Using HTTP does not encrypt data in transit, violating the security requirement.
S3 Secure Partner Access
Securely sharing S3 data with partners involves enforcing HTTPS, restricting access by IP range, and granting granular access to specific prefixes using bucket policies.
- HTTPS ensures data encryption in transit.
- Bucket policies with `aws:SourceIp` restrict access to specific IP ranges.
- Bucket policies with `s3:prefix` limit access to designated object prefixes.
- IAM policies can grant partner roles/users access to the bucket.
Memory trick: HTTPS, IP, and Prefix: 'H'ow 'I' 'P'rotect 'S'3.