SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to ensure that an Amazon S3 bucket is not publicly accessible. Which THREE actions should be taken to prevent public access?
⚠ Common exam trap
The trap here is that candidates might think deleting the bucket policy (option B) is sufficient to prevent public access, but they overlook that public ACLs on objects can still grant public access, and that S3 Block Public Access provides a more comprehensive and enforceable control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the bucket to block new public ACLs using S3 Object Ownership.
Enabling S3 Object Ownership allows you to disable ACLs on the bucket, which prevents new public ACLs from being applied. This is a key step in ensuring that no objects can be made publicly accessible via ACLs, as ACLs are an older access control mechanism that can grant public read/write access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable versioning on the bucket.
Why it's wrong here
Enabling versioning is a data-protection feature that tracks multiple variants of an object to guard against accidental deletion or overwrite. It does not interact with or alter any permission boundary, so if a public ACL or bucket policy already grants anonymous access, that access remains fully effective. Thus, versioning cannot prevent or remediate public exposure.
- ✗
Delete the bucket policy if it exists.
Why it's wrong here
Deleting a bucket policy may remove one potential source of public access, but it leaves object-level ACLs untouched. If any object or the bucket itself has a public ACL, those grants continue to allow anonymous read or write even with no bucket policy present. Additionally, this action is overly broad and could break legitimate cross-account or service-access rules that are unrelated to public exposure.
- ✓
Configure the bucket to block new public ACLs using S3 Object Ownership.
Why this is correct
Setting S3 Object Ownership to Bucket Owner Enforced disables Access Control Lists for the bucket, which prevents new ACLs—including those that would grant public access—from being created. With ACLs disabled, S3 ignores any ACL-based permissions, and all access is controlled exclusively by bucket policies and IAM policies. This is a preventive, proactive measure that stops future public ACL misconfigurations at the source.
- ✓
Review and remove any public ACLs on the bucket and objects.
Why this is correct
Reviewing and removing existing public ACLs is a direct corrective action that addresses the root cause of unintended public exposure. This means inspecting both the bucket-level ACL and the ACLs on every object for grants to the AllUsers or AuthenticatedUsers groups, then stripping those grants. Without this step, any public ACL that was created before preventive controls were enabled will continue to allow anonymous access indefinitely.
- ✓
Use the S3 Block Public Access feature at the bucket level.
Why this is correct
S3 Block Public Access is an enforcement feature that can be configured at the bucket or account level to override all future and existing permissions that could make objects public. Its four settings can block public ACLs, public bucket policies, and cross-account access, and once applied, even an explicit public grant is denied. This provides a robust safety net, though it must be used carefully because it also blocks legitimate public use cases such as static website hosting or public API data.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.