← AWS Solutions Architect Professional: complex decisions
22 / 25 · 90 MIN

S3: access, encryption, and retention

Design private access and prove encrypted, replicated, retained data remains usable by the intended consumer.

Separate ownership from effective authorization

Bucket owner enforced disables ACLs and gives the bucket owner control of objects. An upload with an incompatible ACL can fail with AccessControlListNotSupported; granting s3:* does not repair a request incompatible with that mode. Migrate required access into policies and adapt the client to omit ACLs or use the supported option. A writer from another account does not retain read access merely because it uploaded a file. Validate every identity and operation, including versions. Block Public Access adds protection but does not grant access to authorized applications. S3 combines applicable settings using the most restrictive option. A bucket-only change does not override effective account or organization protection, and a policy that becomes public can affect cross-account access with RestrictPublicBuckets.

Design the path and KMS authorization

A Deny conditioned on aws:SourceVpce can block requests that do not arrive through the specified endpoint, including console paths. Before applying it, validate administration, recovery, and required integrations; do not confuse a private path with granted access. For SSE-KMS, PutObject needs GenerateDataKey, reads need Decrypt, and multipart upload needs both, in addition to S3 permissions and applicable conditions. The key must be in the bucket’s Region. If another account needs to use the key, a customer managed key allows that authorization to be configured; an AWS managed key does not offer the same policy administration. Use a full ARN to avoid resolving an alias name in the caller’s account. Demonstrate writes and reads with actual principals and compare the concrete error with the rejected operation.

Change encryption without inventing retroactive migration

Baseline encryption of new objects does not establish compliance with an internal requirement for a particular key. Changing default configuration does not rewrite old objects either. Inventory the mode and key used by relevant versions and plan any required transformation with validation and cost. S3 Bucket Keys reduce KMS calls but use the bucket ARN as encryption context. A policy limited to each object ARN needs review before the change, preserving intended access boundaries in other layers. Existing objects do not automatically adopt Bucket Keys. KMS events also cease to provide a one-per-object-access record; plan access evidence in the data service. Accept the optimization only after testing consumers and auditing, without assuming a guaranteed savings percentage.

Validate the replica object, not only configuration

Replication of SSE-KMS objects needs explicit configuration and appropriate source and destination permissions. In the simple case without Bucket Keys, the role needs Decrypt on the source key and Encrypt on the destination key; Bucket Key mechanisms add their own requirements. The destination key must be valid and regionally compatible. PutBucketReplication can accept configuration with HTTP 200 even when the specified key cannot support successful replication. Test a representative object and check status, version, encryption, and reads by the recovery role. Multi-Region keys do not remove this S3 flow. In the fictional project, copied metadata and an Enabled rule are intermediate evidence; acceptance requires the recovery consumer to read the necessary dataset within agreed objectives.

Read retention per version and preserve read dependencies

Object Lock protects versions and requires Versioning. This lesson’s deadline exercises use fixed retention; current documentation also describes event-based variable retention, which must not be confused with legal hold. Compliance does not allow retention of a protected version to be shortened, even by root. Governance permits bypass with specific permission and an explicit request indication. Legal hold is independent and remains until authorized removal; removing a hold does not cancel active retention. A new upload can create another version, and a delete marker can hide the current version without deleting protected data. Check versionId, deadline, mode, and holds. Object Lock does not preserve a deleted KMS key: data can remain immutable and become unreadable. Retention design must preserve recovery dependencies too.

Constrain temporary sharing and prove intended access

A presigned URL carries authorization limited by its operation and the signer’s permissions; whoever possesses it can use it under valid conditions. It is not automatically single-use. With temporary credentials, the session can expire before the requested URL lifetime. A signatureAge condition can impose an even shorter limit. In the original model, the URL requests two hours, the session has thirty minutes remaining, and policy allows ten minutes of signature age. With no other restrictions or revocations, new use is limited by ten minutes; the exercise does not generate a real URL. S3 checks expiration at request start, so a download begun before expiry can continue, but a new request after expiry fails. Avoid recording usable URLs in tickets and assess sharing with appropriate positive and negative tests.

requested_seconds = 2 * 60 * 60
credential_seconds_remaining = 30 * 60
policy_signature_age_seconds = 10 * 60
new_request_window_seconds = min(requested_seconds, credential_seconds_remaining, policy_signature_age_seconds) # 600
# Original simplified time model: no earlier revocation or additional deny.
# Not a signed URL, AWS request, or complete authorization simulator.
IN PRACTICE

A fictional team enables Bucket Keys and loses access to some files because its KMS policy requires the object ARN in context. Security reviews the change, preserving application boundaries and rehearsing old and new objects.

Common pitfalls

Opening policies to fix an incompatible ACL; confusing default encryption with migration; accepting replication on HTTP 200; treating retention as a read guarantee; assuming single-use URLs.

Related topics: KMS: authorization and lifecycle

Take this idea with you

Protection is demonstrated when the intended consumer reads the intended version and unwanted access remains blocked.

Create account

Reference: S3 Object Ownership · SAP-C02

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.