- Home
- All questions
- Question 145
AWS Certified Solutions Architect study material · question 145 of 500
Which two AWS Config managed rules give a standing detective control over publicly exposed S3 buckets? Choose two.
Show the answer
Answer: D. s3-bucket-public-read-prohibited
A. s3-bucket-public-write-prohibited
Those two rules watch for public read and write exposure; the versioning and replication rules address durability rather than exposure.
Source: Security best practices for Amazon S3 (Amazon Web Services) — Ensure buckets are not publicly accessible