AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceHard

A large enterprise uses AWS Organizations to manage multiple AWS accounts. The security team wants to ensure that specific compliance requirements are met across all member accounts. Specifically, they need to prevent any IAM user or role in any account from creating S3 buckets that are publicly accessible. What is the most effective way to enforce this policy across all accounts in the organization?

  1. AConfigure S3 bucket policies on all existing and new S3 buckets to deny public access.
  2. BDeploy an AWS Lambda function to periodically check S3 bucket permissions and remediate non-compliant buckets.
  3. CCreate an AWS Organizations Service Control Policy (SCP) to deny the s3:PutBucketAcl and s3:PutBucketPolicy actions that allow public access.
  4. DImplement AWS Config rules in each account to flag S3 buckets with public access and send notifications.
Show answer & explanation

Correct answer: C. Create an AWS Organizations Service Control Policy (SCP) to deny the s3:PutBucketAcl and s3:PutBucketPolicy actions that allow public access.

An AWS Organizations Service Control Policy (SCP) is the most effective way to enforce preventive controls across multiple accounts at the organizational level. By denying specific S3 actions that grant public access, the SCP ensures that no IAM identity in any member account can ever create a publicly accessible S3 bucket, regardless of their individual IAM permissions.

Why the other options are wrong

  • A. Manually configuring S3 bucket policies is not scalable or preventive for new buckets across many accounts; it's a reactive measure.
  • B. A Lambda function for remediation is a reactive control; it allows public buckets to be created first and then remediates them, which doesn't prevent the issue.
  • D. AWS Config rules are detective controls; they identify non-compliant resources after they are created and send notifications, but do not prevent the creation of publicly accessible buckets.

Service Control Policies (SCPs)

SCPs are a type of organization policy that you can use to manage permissions in your organization. They offer central control over the maximum available permissions for all accounts in your organization.

  • Apply to all IAM users and roles in affected accounts.
  • Act as guardrails, setting maximum permissions.
  • Cannot grant permissions; they only restrict them.
  • Preventive security control.

Memory trick: SCPs: The Organization's Grand Gatekeeper, saying 'No' to bad behavior.

More Security and Compliance questions