Question 1 · choose 1
A bucket holds payment files that are read and written by applications in several AWS accounts. A new standard requires that every request to the bucket, from any principal, uses HTTPS with TLS 1.2 or later. What should the security team implement?
- ATurn on S3 Block Public Access settings for the bucket and the account
- BSet default encryption to SSE-KMS with a customer managed key and S3 Bucket Keys
- CAttach an SCP that denies S3 actions whenever aws:SecureTransport is false
- DBucket policy denies if aws:SecureTransport is false or s3:TlsVersion is below 1.2
Show the answer and why
ATurn on S3 Block Public Access settings for the bucket and the account
Incorrect
Block Public Access limits public grants. It does not control which protocol or TLS version a request uses.
BSet default encryption to SSE-KMS with a customer managed key and S3 Bucket Keys
Incorrect
Default encryption protects objects at rest. It says nothing about how requests travel to the bucket.
CAttach an SCP that denies S3 actions whenever aws:SecureTransport is false
Incorrect
An SCP applies only to principals in the organization's member accounts, not to every principal that can reach the bucket.
DBucket policy denies if aws:SecureTransport is false or s3:TlsVersion is below 1.2
Correct
The bucket policy applies to every request to the bucket; one deny blocks plain HTTP and the other blocks TLS versions older than 1.2.
Enforce transport rules where every request is evaluated: the bucket policy. aws:SecureTransport rules out HTTP, and s3:TlsVersion sets the minimum TLS version.
AWS documentation
- Bucket policy examples using condition keys (opens in a new tab)
- Security best practices for Amazon S3 (opens in a new tab)
- Blocking public access to your Amazon S3 storage (opens in a new tab)
- Setting default server-side encryption behavior for Amazon S3 buckets (opens in a new tab)
- Service control policies (SCPs) (opens in a new tab)