nerdexam
Amazon

SCS-C03 · Question #76

A company has AWS accounts in an organization in AWS Organizations. An Amazon S3 bucket in one account is publicly accessible. A security engineer must remove public access and ensure the bucket canno

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #76. The question stem and answer options stay visible for context.

Submitted by klara.se· Mar 6, 2026Infrastructure Security

Question

A company has AWS accounts in an organization in AWS Organizations. An Amazon S3 bucket in one account is publicly accessible. A security engineer must remove public access and ensure the bucket cannot be made public again. Which solution will meet these requirements?

Options

  • AEnforce KMS encryption and deny s3:GetObject by SCP.
  • BEnable PublicAccessBlock and deny s3:GetObject by SCP.
  • CEnable PublicAccessBlock and deny s3:PutPublicAccessBlock by SCP.
  • DEnable Object Lock governance and deny s3:PutPublicAccessBlock by SCP.

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#S3 Block Public Access#SCP deny#public access prevention#bucket security
Full SCS-C03 Practice