- Home
- All questions
- Question 30
AWS Certified Solutions Architect study material · question 30 of 500
An organization wants to guarantee that no S3 bucket in any member account can be made public. Which two actions achieve this? Choose two.
Show the answer
Answer: C. Apply an organization-level Block Public Access policy at the organization root
D. Enable all four Block Public Access settings on each bucket
Block Public Access at organization and bucket level both enforce the restriction, and S3 applies whichever combination is most restrictive.
Source: Security best practices for Amazon S3 (Amazon Web Services) — Organization-level Block Public Access