Courseiva
Security and Compliance →easyMultiple Select

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to ensure that an Amazon S3 bucket is not publicly accessible. Which THREE actions should be taken to prevent public access?

⚠ Common exam trap

The trap here is that candidates might think deleting the bucket policy (option B) is sufficient to prevent public access, but they overlook that public ACLs on objects can still grant public access, and that S3 Block Public Access provides a more comprehensive and enforceable control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the bucket to block new public ACLs using S3 Object Ownership.

Enabling S3 Object Ownership allows you to disable ACLs on the bucket, which prevents new public ACLs from being applied. This is a key step in ensuring that no objects can be made publicly accessible via ACLs, as ACLs are an older access control mechanism that can grant public read/write access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable versioning on the bucket.

    Why it's wrong here

    Enabling versioning is a data-protection feature that tracks multiple variants of an object to guard against accidental deletion or overwrite. It does not interact with or alter any permission boundary, so if a public ACL or bucket policy already grants anonymous access, that access remains fully effective. Thus, versioning cannot prevent or remediate public exposure.

  • ✗

    Delete the bucket policy if it exists.

    Why it's wrong here

    Deleting a bucket policy may remove one potential source of public access, but it leaves object-level ACLs untouched. If any object or the bucket itself has a public ACL, those grants continue to allow anonymous read or write even with no bucket policy present. Additionally, this action is overly broad and could break legitimate cross-account or service-access rules that are unrelated to public exposure.

  • ✓

    Configure the bucket to block new public ACLs using S3 Object Ownership.

    Why this is correct

    Setting S3 Object Ownership to Bucket Owner Enforced disables Access Control Lists for the bucket, which prevents new ACLs—including those that would grant public access—from being created. With ACLs disabled, S3 ignores any ACL-based permissions, and all access is controlled exclusively by bucket policies and IAM policies. This is a preventive, proactive measure that stops future public ACL misconfigurations at the source.

  • ✓

    Review and remove any public ACLs on the bucket and objects.

    Why this is correct

    Reviewing and removing existing public ACLs is a direct corrective action that addresses the root cause of unintended public exposure. This means inspecting both the bucket-level ACL and the ACLs on every object for grants to the AllUsers or AuthenticatedUsers groups, then stripping those grants. Without this step, any public ACL that was created before preventive controls were enabled will continue to allow anonymous access indefinitely.

  • ✓

    Use the S3 Block Public Access feature at the bucket level.

    Why this is correct

    S3 Block Public Access is an enforcement feature that can be configured at the bucket or account level to override all future and existing permissions that could make objects public. Its four settings can block public ACLs, public bucket policies, and cross-account access, and once applied, even an explicit public grant is denied. This provides a robust safety net, though it must be used carefully because it also blocks legitimate public use cases such as static website hosting or public API data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.