Study. uk . com
  1. Home
  2. All questions
  3. Question 31

AWS Certified Solutions Architect study material · question 31 of 500

An organization enables Block Public Access at the organization level, but one bucket has it disabled at bucket level. What protection does that bucket have?

  1. The conflict prevents any access to the bucket at all
  2. It stays protected, because the more restrictive organization setting prevails
  3. It becomes public, because the bucket-level setting is more specific
  4. It is protected only for new objects, not existing ones
Show the answer

Answer: B. It stays protected, because the more restrictive organization setting prevails

S3 evaluates access point, bucket, account and organization settings together and enforces the most restrictive combination.

Source: Blocking public access to your Amazon S3 storage (Amazon Web Services) — Blocking public access to your Amazon S3 storage

Challenge yourself on this topic → Study as cards