Which action is a security best practice for granting applications access to sensitive data stored in an Amazon S3 bucket?
Choose an answer
Tap an option to check your answer.
Correct answer: Use IAM roles for applications that need access to the bucket..
Why this is the answer
Using IAM roles for applications is a security best practice because it adheres to the principle of least privilege and avoids embedding credentials directly within application code. IAM roles provide temporary, rotating credentials, reducing the risk of long-lived access keys being compromised. Enabling S3 Cross-Region Replication (CRR) is for data durability and disaster recovery, not for controlling application access. AWS WAF (Web Application Firewall) protects web applications from common exploits and is not designed to control programmatic access to S3 buckets. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it doesn't prevent access; it alerts you to potential issues.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed