Which TWO actions improve the security of an S3 bucket that stores sensitive data?
Trap 1: Enable S3 Transfer Acceleration.
Transfer Acceleration speeds uploads and downloads through edge locations; it adds no authorisation, encryption or monitoring control over the sensitive objects. It tempts because it is a legitimate S3 feature, correct when the requirement is improving throughput for geographically distant clients.
Trap 2: Configure a lifecycle policy to transition objects to Glacier.
Lifecycle transitions to Glacier change storage class and cost, not access control, encryption or logging, so sensitive objects remain equally exposed. It tempts because lifecycle policies are a genuine S3 management feature, correct when the goal is archival or cost reduction rather than security hardening.
Trap 3: Enable S3 Select to filter data.
S3 Select filters object contents during retrieval; it neither restricts who may read objects nor encrypts them, so it leaves the bucket's exposure unchanged. It tempts because it is a real S3 capability, appropriate when the requirement is reducing data transferred for analytics queries.
- A
Enable default encryption with SSE-S3 or SSE-KMS.
SSE-S3 or SSE-KMS encrypts objects at rest, so data written to the bucket is unreadable without the corresponding key. This directly satisfies the sensitive-data protection requirement, mitigating exposure if storage media or snapshots are compromised.
- B
Block all public access using the S3 Block Public Access feature.
S3 Block Public Access overrides bucket policies and ACLs that would otherwise grant anonymous or public access, closing accidental exposure paths. It satisfies the sensitive-data constraint by preventing any public read or write regardless of individual object permissions.
- C
Enable S3 Transfer Acceleration.
Why it fails: Transfer Acceleration speeds uploads and downloads through edge locations; it adds no authorisation, encryption or monitoring control over the sensitive objects. It tempts because it is a legitimate S3 feature, correct when the requirement is improving throughput for geographically distant clients.
- D
Configure a lifecycle policy to transition objects to Glacier.
Why it fails: Lifecycle transitions to Glacier change storage class and cost, not access control, encryption or logging, so sensitive objects remain equally exposed. It tempts because lifecycle policies are a genuine S3 management feature, correct when the goal is archival or cost reduction rather than security hardening.
- E
Enable S3 Select to filter data.
Why it fails: S3 Select filters object contents during retrieval; it neither restricts who may read objects nor encrypts them, so it leaves the bucket's exposure unchanged. It tempts because it is a real S3 capability, appropriate when the requirement is reducing data transferred for analytics queries.