Block public access on the bucket and use an SCP to deny disabling Public Access Block

Answer Correct answer: C — enable S3 Block Public Access on the bucket and an SCP denying s3:PutPublicAccessBlock keeps it private permanently.

A company has AWS accounts that are in an organization in AWS Organizations. An Amazon S3 bucket in one of the accounts is publicly accessible. A security engineer must change the configuration so that the S3 bucket is no longer publicly accessible. The security engineer also must ensure that the S3 bucket cannot be made publicly accessible in the future. Which solution will meet these requirements?

  1. Configure the S3 bucket to use an AWS Key Management Service (AWS KMS) key. Encrypt all objects in the S3 bucket by creating a bucket policy that enforces encryption. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
  2. Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:GetObject action for the OU that contains the AWS account.
  3. Enable the PublicAccessBlock configuration on the S3 bucket. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account. Correct Answer
  4. Configure the S3 bucket to use S3 Object Lock in governance mode. Configure an SCP to deny the s3:PutPublicAccessBlock action for the OU that contains the AWS account.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

S3 Block Public Access is the native control that closes public ACLs and policies. An SCP denying s3:PutPublicAccessBlock acts as an immutable guardrail: even accounts with full S3 permissions cannot turn the block off, guaranteeing the bucket stays private. Denying s3:GetObject instead (option B) would make the bucket unusable for everyone, not just the public.

An S3 bucket is publicly accessible and must be made private and kept private. Enabling S3 Block Public Access on the bucket stops all public access paths. To prevent anyone from re-enabling public access later, an SCP attached to the OU denies s3:PutPublicAccessBlock, so the block configuration cannot be removed or weakened—ensuring the bucket can never be made public again.

Denying s3:GetObject via SCP (option B)—that blocks all reads, including legitimate private access, rendering the bucket unusable. Or using Object Lock (option D), which protects against deletion/overwrite but does not address public-access configuration.

Community Discussion (6 comments)

nznzwell 👍 1 Selected: C
For those who chose B, how can it be correct? an SCP denying s3:GetObject will deny access to the objects regardless if it is from the public or within the account... B will render the bucket inaccessible.
helloworldabc 👍 1
just B
Olaunfazed 👍 1
Answer is B Enabling the PublicAccessBlock configuration on the S3 bucket prevents public access. Additionally, configuring an SCP (Service Control Policy) to deny the s3:GetObject action for the organizational unit (OU) containing the AWS account ensures that the bucket remains private.
sema2232 👍 1
why not B?
aescudero51 👍 2 Selected: C
Enable PublicAccessBlock Configuration: https://aws.amazon.com/s3/features/block-public-access/?nc1=h_ls Configure an SCP (Service Control Policy): An SCP is a policy that you can attach to an AWS Organization, organizational unit (OU), or an account. It acts as a guardrail to control permissions across accounts. In your case, you want to deny the s3:PutPublicAccessBlock action for the OU containing your AWS account. Go to the AWS Organizations console. Navigate to the OU that contains your account. Create a new SCP or edit an existing one. Add a statement that denies the s3:PutPublicAccessBlock action for the relevant S3 buckets. Attach the SCP to the OU. Ensure that your AWS account is part of the OU.
Zek 👍 1
C Enable the PublicAccessBlock & use SCP to deny the s3:PutPublicAccessBlock action

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Enabling Block Public Access on the bucket removes its current public accessibility. The SCP denying s3:PutPublicAccessBlock prevents any principal in the OU from disabling or modifying that block, so the bucket cannot be made public in the future—meeting both requirements. This is a clean preventive guardrail.

Why the Other Options Are Wrong

B denies s3:GetObject, which would deny all object reads (public and private), making the bucket inaccessible to legitimate users—not the goal. A mixes KMS encryption and an S3 GetObject SCP, neither of which blocks public configuration. D uses Object Lock, which guards against deletion/overwrite, not public-access settings. C is the correct pair.

Community Comment Notes

Community voted C (100). Commenters noted B's GetObject deny would make the bucket unusable, whereas denying PutPublicAccessBlock locks the block in place. C combines Block Public Access with an SCP guardrail against disabling it.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide