A healthcare organization is storing protected health information (PHI) in a cloud object storage service. They want to ensure that if a storage bucket is accidentally made public, the data remains unreadable. Which combination of controls best addresses this risk?
Trap 1: Apply data classification labels and enable DLP scanning
Classification labels and DLP scanning identify and monitor sensitive data but do not render objects unreadable; a public bucket would still expose plaintext PHI. They are tempting because both are data-governance controls, and would be correct for visibility and compliance reporting rather than cryptographic protection.
Trap 2: Enable bucket versioning and cross-region replication
Versioning and cross-region replication preserve and duplicate objects; neither encrypts content, so a public bucket still exposes readable PHI. They are tempting as resilience controls, and would be correct for durability, ransomware recovery or regional failover, not for confidentiality against accidental exposure.
Trap 3: Use pre-signed URLs and IAM policies
Pre-signed URLs and IAM policies govern access requests, but a bucket made public bypasses those controls, leaving objects readable. They are tempting because they are standard access-management tools, and would be correct for granting time-limited or least-privilege access, not for rendering data unreadable at rest.
- A
Enable server-side encryption with AES-256 and block public access
Server-side AES-256 encryption renders object data unreadable at rest, so even if a bucket policy is misconfigured and exposes objects publicly, the ciphertext cannot be decrypted without keys held in the KMS. Blocking public access adds a preventive layer, but encryption is what satisfies the 'remains unreadable' constraint.
- B
Apply data classification labels and enable DLP scanning
Why it fails: Classification labels and DLP scanning identify and monitor sensitive data but do not render objects unreadable; a public bucket would still expose plaintext PHI. They are tempting because both are data-governance controls, and would be correct for visibility and compliance reporting rather than cryptographic protection.
- C
Enable bucket versioning and cross-region replication
Why it fails: Versioning and cross-region replication preserve and duplicate objects; neither encrypts content, so a public bucket still exposes readable PHI. They are tempting as resilience controls, and would be correct for durability, ransomware recovery or regional failover, not for confidentiality against accidental exposure.
- D
Use pre-signed URLs and IAM policies
Why it fails: Pre-signed URLs and IAM policies govern access requests, but a bucket made public bypasses those controls, leaving objects readable. They are tempting because they are standard access-management tools, and would be correct for granting time-limited or least-privilege access, not for rendering data unreadable at rest.