Study. uk . com
  1. Home
  2. All questions
  3. Question 30

AWS Certified Solutions Architect study material · question 30 of 500

An organization wants to guarantee that no S3 bucket in any member account can be made public. Which two actions achieve this? Choose two.

  1. Enable S3 Versioning on every bucket
  2. Set a lifecycle rule that expires public objects
  3. Apply an organization-level Block Public Access policy at the organization root
  4. Enable all four Block Public Access settings on each bucket
Show the answer

Answer: C. Apply an organization-level Block Public Access policy at the organization root
D. Enable all four Block Public Access settings on each bucket

Block Public Access at organization and bucket level both enforce the restriction, and S3 applies whichever combination is most restrictive.

Source: Security best practices for Amazon S3 (Amazon Web Services) — Organization-level Block Public Access

Challenge yourself on this topic → Study as cards