QuestionQ45

Incident Response

A healthcare company stores more than 1 million patient records in an Amazon S3 bucket. The patient records include personally identifiable information (PII). The S3 bucket contains hundreds of terabytes of data.

A security engineer receives an alert triggered by an Amazon GuardDuty Exfiltration:S3/AnomalousBehavior finding. The security engineer confirms that an attacker is using temporary credentials obtained from a compromised Amazon EC2 instance that has s3:GetObject permissions for the S3 bucket. The attacker has started downloading the bucket contents. The security engineer contacts a development team, which will require 4 hours to implement and deploy a fix.

The security engineer must immediately prevent the attacker from downloading additional data from the S3 bucket.

Which solution will meet this requirement?

Explanation

A temporary S3 bucket policy that explicitly denies read access to every principal prevents s3:GetObject downloads even when the EC2 role otherwise allows them. Explicit Deny overrides Allow during AWS policy evaluation, and applying the denial at the bucket protects against both the already compromised credentials and any newly issued credentials from the compromised instance until the vulnerability is remediated.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!