AWS Certified Solutions Architect – Associate (SAA-C03) — Question 401

An image-hosting company stores its objects in Amazon S3 buckets. The company wants to avoid accidental exposure of the objects in the S3 buckets to the public. All S3 objects in the entire AWS account need to remain private.

Which solution will meet these requirements?

Answer options

Correct answer: D

Explanation

Configuring S3 Block Public Access at the AWS account level ensures that no S3 buckets within the account can be made public, while using an AWS Organizations SCP prevents IAM users from disabling this protection. Other options like Amazon GuardDuty, AWS Trusted Advisor, or AWS Resource Access Manager do not offer preventative enforcement at the account level and rely on reactive detection or manual intervention, which fails to guarantee immediate and absolute prevention of accidental exposure.