Q: 13
A company has AWS accounts in an organization in AWS Organizations. An Amazon S3 bucket in one
account is publicly accessible. A security engineer must remove public access and ensure the bucket
cannot be made public again.
Which solution will meet these requirements?
Options
Discussion
Option B looks right to me. If you enable PublicAccessBlock and then deny s3:GetObject at the org level with an SCP, that should stop public reads, and Block Public Access covers other risks. Had something like this in a mock and B was the answer there. Maybe I'm missing something?
C vs B, but C is better protection. PublicAccessBlock needs to stay enforced, so denying s3:PutPublicAccessBlock in the SCP keeps it locked down. B only blocks current access but admins could disable the block later. Pretty sure C is the intent here.
Be respectful. No spam.