Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

An organization requires that all Amazon S3 buckets block public access entirely. A SysOps administrator needs to ensure that no bucket can be made public, even accidentally. Which approach enforces this control at the organizational level?

⚠ Common exam trap

Test-takers frequently confuse detective controls (like AWS Config rules) with preventive controls (like SCPs and account-level Block Public Access), assuming that detecting and auto-remediating public buckets is equivalent to preventing them from ever becoming public.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access at the account level and attach an SCP to deny changes to it.

S3 Block Public Access at the account level provides a centralized, immutable control that prevents any bucket in the account from being made public, regardless of bucket policies or ACLs. Attaching an SCP (Service Control Policy) to deny changes to these settings ensures that even administrators with full IAM permissions cannot disable the block, enforcing the control at the organizational level across all accounts in the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply an S3 Bucket Policy on each bucket that denies public access.

    Why it's wrong here

    A per-bucket bucket policy that denies public access is a fragmented, copy-paste control that must be manually applied to every bucket. It can be easily omitted for new buckets or removed by any user with s3:PutBucketPolicy permission. More importantly, a bucket policy cannot block all public exposure — it doesn't affect public ACLs or existing policy grants, whereas S3 Block Public Access enforces a blanket service-level denial.

  • ✗

    Use an AWS Config managed rule 's3-bucket-public-read-prohibited' to detect and remediate public buckets.

    Why it's wrong here

    The AWS Config managed rule s3-bucket-public-read-prohibited is purely detective; it evaluates the configuration after the fact and only reports non-compliance. It can trigger automatic remediation, but remediation runs after the violation and does not prevent the public access from being created, allowing a window where the data is exposed. It also only checks read access, so a bucket with public write or public ACLs may not be flagged, while account-level Block Public Access proactively prevents all such exposure.

  • ✓

    Enable S3 Block Public Access at the account level and attach an SCP to deny changes to it.

    Why this is correct

    This is the only correct answer because it provides a centralized, preventive, and tamper-proof control. Enabling S3 Block Public Access at the account level immediately denies all public read/write access to every current and future bucket in that account. Attaching an SCP that denies s3:PutAccountPublicAccessBlock and s3:PutBucketPublicAccessBlock prevents users—even those with full S3 permissions—from modifying those settings, because SCPs cannot be overridden by IAM policies within the member account.

  • ✗

    Create an IAM policy that denies s3:PutBucketPolicy for all users.

    Why it's wrong here

    An IAM policy that denies s3:PutBucketPolicy for all users fails to block public access granted through S3 access control lists (ACLs), which are a separate authorization path. It also does not cover actions like s3:PutObjectAcl or s3:PutBucketAcl, and it cannot prevent the account root user from modifying the policy. S3 Block Public Access is the appropriate service-wide control because it blocks all public access mechanisms regardless of how the request is made.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.