After a recent security audit involving Amazon S3, a company has asked assistance reviewing its S3 buckets to determine whether data is properly secured.
The first S3 bucket on the list has the following bucket policy.
Is this bucket policy sufficient to ensure that the data is not publicity accessible?
A . Yes, the bucket policy makes the whole bucket publicly accessible despite now the S3 bucket ACL or object ACLs are configured.
B . Yes, none of the data in the bucket is publicity accessible, regardless of how the S3 bucket ACL and object ACLs are configured.
C . No, the IAM user policy would need to be examined first to determine whether any data is publicly accessible.
D . No, the S3 bucket ACL and object ACLs need to be examined first to determine whether any data is publicly accessible.
Answer: A
Leave a Reply