7 min read · about 55 min with practice3 quick checks≈2% of the testCore: Core: tested on most papers
Reading is free. Sign in to tick off lessons, keep your place and track your mastery.
Amazon S3 is the most-tested storage service on SAA-C03. In Domain 1 the questions are not about storage classes. They ask how to keep a bucket private, how to share data safely, and how to make objects impossible to delete. Expect two to four questions, often with a short bucket policy in the stem.
By the end you’ll be able to
Control access with bucket policies, Block Public Access, Object Ownership (ACLs disabled) and S3 access points
Grant temporary object access with presigned URLs and serve private content through CloudFront with origin access control
Protect against deletion and overwrite with versioning, MFA Delete and Object Lock (governance vs compliance mode, legal hold)
Meet retention and residency requirements with replication (SRR/CRR), lifecycle rules and Object Lock
What the exam asks
Serve a private bucket only through CloudFront → origin access control (OAC).
Give short-lived access to someone without AWS credentials → a presigned URL.
Share one bucket with many teams or accounts without a huge bucket policy → S3 access points.
Allow the whole organization and nobody else → the aws:PrincipalOrgID condition.
Reject plain HTTP → Deny when aws:SecureTransport is false.
Recover from accidental deletes or overwrites → versioning.
WORM storage that nobody can shorten → Object Lock compliance mode. If a few admins need an override → governance mode. To keep objects until an unknown date → a legal hold.
An independent copy in another account or Region → replication with owner override, plus Batch Replication for existing objects.
Core ideas
How S3 access is decided
IAM identity policies, bucket policies, access point policies, VPC endpoint policies and (legacy) ACLs are evaluated together, and an explicit Deny anywhere wins. Within one account, either an identity policy or the bucket policy can allow a request. Across accounts both must allow it: the bucket or access point policy must trust the external principal, and that principal’s own IAM policy must allow the action. For SSE-KMS objects, the KMS key policy must also allow kms:Decrypt.
Secure defaults for new buckets
Setting
Default today
Effect
Block Public Access
All four settings on
Public ACLs and public bucket policies are blocked
Object Ownership
Bucket owner enforced
ACLs are disabled, and the bucket owner owns every object
Default encryption
SSE-S3
Every new object is encrypted at rest
SSE-C
Blocked (since April 2026)
Must be turned on deliberately
vii.Check your understanding
3 questions on S3 access control and data protection. Every option is explained once you answer.
Sign in to try the quick check
Answers are checked on our side, every option is explained, and your result feeds your mastery for this topic. It’s free.
The first 3 of 10 cards for this topic. Sign in and finish the lesson to review them with spaced repetition.
PromptCard 1 of 3
Object Lock governance mode vs compliance mode
Block Public Access at the account level overrides bucket settings, so it answers “no bucket in this account may ever become public”. Its BlockPublicPolicy setting rejects any attempt to attach a public bucket policy.
Switching an older bucket to Bucket owner enforced disables ACLs and makes the bucket owner the owner of all existing and future objects. That fixes the classic “we cannot read the files our partner uploaded” problem with no change on the partner’s side.
Bucket policy condition keys to know
Key
Typical use
aws:SecureTransport
Deny requests that do not use HTTPS
aws:PrincipalOrgID
Allow every account in the organization, including future ones
aws:SourceVpce / aws:SourceVpc
Allow access only through one VPC endpoint or VPC
AWS:SourceArn (with the CloudFront service principal)
Allow only one CloudFront distribution (OAC)
s3:x-amz-server-side-encryption
Require a specific encryption type on upload
Access points
An access point is a named endpoint with its own policy, and it can be limited to a single VPC. Give each application or team its own access point, and delegate access control from the bucket policy to the access points. Many small policies are easier to manage than one oversized bucket policy that everyone edits.
Temporary and edge access
Presigned URLs lend the signer’s permissions for a limited time: up to 7 days when signed with IAM user credentials, and never longer than the temporary credentials that signed them. Use one for a single object and a user without AWS credentials.
CloudFront with OAC keeps the bucket private. The bucket policy allows the cloudfront.amazonaws.com service principal, with a condition on the distribution’s ARN. OAC works with SSE-KMS objects (add CloudFront to the key policy), in all Regions and for uploads. The older origin access identity (OAI) does not, so OAI is a legacy answer.
Protecting against deletion and overwrite
Feature
Protects against
Who can override
Versioning
Overwrites and deletes (a delete adds a delete marker)
Anyone allowed to delete specific versions
MFA Delete
Permanent version deletes and versioning changes without MFA
The root user with MFA. Only the root user can enable it, through the API or CLI
Object Lock, governance mode
Deletes and overwrites until the retention date
Users with s3:BypassGovernanceRetention
Object Lock, compliance mode
Deletes, overwrites and shortening the retention
Nobody, not even the root user, until the date passes
Legal hold
Deletes while the hold is on, with no end date
Users with s3:PutObjectLegalHold can remove it
Object Lock needs versioning and protects object versions. A bucket’s default retention applies only to objects written after it is set. A legal hold is separate from the retention period, which makes it the tool for litigation with an unknown end date.
Replication for protection
Same-Region and Cross-Region Replication need versioning on both buckets and copy only new objects. Use S3 Batch Replication for objects that already exist. Delete markers are replicated only if you turn that on, and deletes of specific versions are never replicated. For a copy in a separate security account, use owner override so that the destination account owns the replicas. S3 Replication Time Control adds a 15-minute SLA.
Worked examples
Exam technique
Ask who needs access. No AWS credentials means a presigned URL. CloudFront only means OAC. The whole organization means aws:PrincipalOrgID. Many applications means access points.
Ask who must not be able to delete. Nobody, including root, means compliance mode. Everyone except a few admins means governance mode with the bypass permission. Until an unknown date means a legal hold.
Options that turn off Block Public Access or turn on ACLs to share across accounts are almost always wrong. A grant to a named principal in another account is not public.
Common mistakes
Quick recap
Cross-account access needs the bucket (or access point) policy and the caller’s IAM policy, plus the key policy for SSE-KMS.
New buckets default to Block Public Access on, ACLs disabled and SSE-S3.
Use aws:SecureTransport to require TLS and aws:PrincipalOrgID to allow the organization.
Presigned URLs give short-lived access to a single object. OAC keeps a private origin behind CloudFront.
Versioning recovers from mistakes. Compliance mode cannot be overridden, governance mode can be bypassed with permission, and a legal hold has no end date.
Replication copies only new objects. Use Batch Replication for existing objects and owner override for a separate security account.