Company policy now forbids any S3 data in the account from being publicly accessible. What action should a SysOps administrator take to enforce this requirement across the account?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable S3 Block Public Access at the account level..
Why this is the answer
Enabling S3 Block Public Access at the account level is the most effective and comprehensive way to enforce a company policy forbidding public S3 data. This feature provides a centralized control that overrides individual bucket and object permissions, ensuring no S3 data in the account can ever be publicly accessible, regardless of how buckets or objects are configured. Creating an Amazon EventBridge rule to enforce private S3 objects would be reactive and complex to manage, as it would require defining rules for various S3 actions and potentially race conditions. Amazon Inspector is a security assessment service, not a remediation tool for S3 public access, and it doesn't automatically reset ACLs. S3 Object Lambda modifies data as it's retrieved, not as it's stored, and is not designed for enforcing public access policies across an entire account.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed