AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesHard

A global enterprise needs to securely share large datasets stored in an Amazon S3 bucket with external partners. The partners do not have AWS accounts, and the company wants to avoid giving them direct IAM user access. The solution must ensure that partners can only access specific prefixes within the S3 bucket and that access is granted for a limited time. Which is the MOST secure and efficient method to achieve this?

  1. ACreate IAM users for each partner and configure IAM policies with least privilege access.
  2. BGenerate pre-signed URLs for specific S3 objects or prefixes, with an expiration time, and share these URLs with partners.
  3. CSet up an SFTP server on an EC2 instance, transfer data to it, and provide SSH access to partners.
  4. DGrant public read access to the S3 bucket and provide partners with the URL.
Show answer & explanation

Correct answer: B. Generate pre-signed URLs for specific S3 objects or prefixes, with an expiration time, and share these URLs with partners.

Pre-signed URLs are the most secure and efficient method here. They grant temporary, time-limited access to specific S3 objects or prefixes without requiring partners to have AWS credentials. This meets the requirements for restricted access to specific prefixes and limited time, without creating IAM users for external parties.

Why the other options are wrong

  • A. Creating IAM users for external partners is generally not recommended for security and management overhead, especially when partners don't have AWS accounts, and it doesn't inherently provide time-limited access without additional mechanisms.
  • C. Setting up and managing an SFTP server on EC2 introduces operational overhead, security patching responsibilities, and is less efficient than directly leveraging S3's native sharing capabilities for large datasets, and doesn't inherently provide time-limited access without additional complex configurations.
  • D. Public read access makes the data available to anyone, which violates the security requirement for controlled access to specific partners.

S3 Pre-signed URLs

An Amazon S3 pre-signed URL is a URL that you can share with others to grant them temporary access to a specific S3 object or prefix, without requiring them to have AWS credentials.

  • Grants temporary access to objects/prefixes.
  • Does not require AWS credentials for the recipient.
  • Expiration time can be set, enhancing security.

Memory trick: Pre-signed URLs: Perfect for Partners, Precise and Temporary.

More Design Secure Architectures questions