A company stores sensitive audit reports in an Amazon S3 bucket. An external auditor needs to download a specific report for a compliance review. The auditor does not have an AWS account and will only need access for 48 hours. The company wants to provide a secure, time-limited link that allows the auditor to download the file directly from S3 without making the bucket public or requiring the auditor to authenticate with AWS. Which AWS feature should the company use to meet these requirements?
An S3 presigned URL is the correct solution. It allows the company to generate a URL that provides temporary access to a specific S3 object. The URL includes a signature that expires after the specified time (48 hours). The auditor can simply use the URL to download the file without needing AWS credentials or any other authentication, and the bucket remains private.
Why this answer
An S3 presigned URL allows the company to grant temporary, time-limited access to a specific object in a private S3 bucket without requiring the auditor to have AWS credentials. By generating the URL with a 48-hour expiration, the company meets the exact requirement for secure, time-bound access. The auditor can download the file directly via HTTPS using the presigned URL, which embeds the necessary authentication information.
Exam trap
The trap here is that candidates may overcomplicate the solution by choosing CloudFront signed URLs (Option D) because they associate signed URLs with security, but the question explicitly requires a direct S3 download without additional services, making the simpler S3 presigned URL the correct choice.
Why the other options are wrong
The auditor does not have an AWS account, so an S3 bucket policy restricting by IP address would still require the auditor to have AWS credentials to access the bucket, which they lack.
The auditor does not have an AWS account, so cross-account access via an IAM role is not possible. IAM roles require the external user to have an AWS account to assume the role.
CloudFront signed URLs require the auditor to access the content through CloudFront, not directly from S3, and involve setting up a CloudFront distribution with an origin access identity, which is unnecessary for a simple, time-limited direct S3 download.