AWS Certified Developer – Associate (DVA-C02)SecurityMedium

A developer is building a mobile application that needs to retrieve images stored in an Amazon S3 bucket. The images are private and should only be accessible for a limited time by authenticated users. The application should not expose AWS credentials directly to the client. How can the developer provide temporary, secure access to these S3 objects?

  1. ACreate an S3 bucket policy that grants public read access for a short period.
  2. BUse an AWS Lambda function to stream the images to the mobile application.
  3. CConfigure an IAM role with read permissions and provide its temporary credentials to the mobile app.
  4. DGenerate S3 pre-signed URLs for the images, specifying an expiration time.
Show answer & explanation

Correct answer: D. Generate S3 pre-signed URLs for the images, specifying an expiration time.

Generating S3 pre-signed URLs allows temporary, time-limited access to private S3 objects without requiring the client to have AWS credentials, directly meeting the requirements for secure and temporary access.

Why the other options are wrong

  • A. Granting public read access, even for a short period, is generally not recommended for sensitive private data and does not provide authentication or granular control per user.
  • B. Using a Lambda function to stream images adds unnecessary complexity, latency, and cost compared to the native S3 pre-signed URL feature, and doesn't inherently solve the temporary access problem without additional logic.
  • C. Providing temporary IAM credentials directly to a mobile application is less secure than pre-signed URLs, as it gives the client broader permissions than just accessing a specific object, and managing these credentials on the client side is complex.

S3 Pre-Signed URLs

S3 pre-signed URLs grant temporary access to a private S3 object (read or write) using standard HTTP requests. The URL contains security credentials and an expiration time, allowing access without exposing AWS credentials.

  • Temporary access to private S3 objects.
  • Does not expose AWS credentials to client.
  • URL includes an expiration time.
  • Can be generated for read or write operations.

Memory trick: Pre-signed URLs are the temporary keys for S3's private doors.

More Security questions