AWS Certified Developer – Associate (DVA-C02)SecurityMedium
A developer is building a mobile application that needs to retrieve images stored in an Amazon S3 bucket. The images are private and should only be accessible for a limited time by authenticated users. The application should not expose AWS credentials directly to the client. How can the developer provide temporary, secure access to these S3 objects?
- ACreate an S3 bucket policy that grants public read access for a short period.
- BUse an AWS Lambda function to stream the images to the mobile application.
- CConfigure an IAM role with read permissions and provide its temporary credentials to the mobile app.
- DGenerate S3 pre-signed URLs for the images, specifying an expiration time.
Show answer & explanationAnswer & explanation
Correct answer: D. Generate S3 pre-signed URLs for the images, specifying an expiration time.
Generating S3 pre-signed URLs allows temporary, time-limited access to private S3 objects without requiring the client to have AWS credentials, directly meeting the requirements for secure and temporary access.
Why the other options are wrong
- A. Granting public read access, even for a short period, is generally not recommended for sensitive private data and does not provide authentication or granular control per user.
- B. Using a Lambda function to stream images adds unnecessary complexity, latency, and cost compared to the native S3 pre-signed URL feature, and doesn't inherently solve the temporary access problem without additional logic.
- C. Providing temporary IAM credentials directly to a mobile application is less secure than pre-signed URLs, as it gives the client broader permissions than just accessing a specific object, and managing these credentials on the client side is complex.
S3 Pre-Signed URLs
S3 pre-signed URLs grant temporary access to a private S3 object (read or write) using standard HTTP requests. The URL contains security credentials and an expiration time, allowing access without exposing AWS credentials.
- Temporary access to private S3 objects.
- Does not expose AWS credentials to client.
- URL includes an expiration time.
- Can be generated for read or write operations.
Memory trick: Pre-signed URLs are the temporary keys for S3's private doors.