問題文
A storage bucket that was found to hold customer records has been made readable to anyone, and reads from unfamiliar addresses have already occurred. Which response is appropriate?
選択肢
- Close the public access so that no further reads are possible, and then treat the records that were already read as having been disclosed.
- Enable encryption at rest on the bucket, because encrypted contents cannot be read by anyone who reaches them and this addresses the exposure without changing the access configuration that other systems may depend on.
- Close the public access, which resolves the situation completely because no data can be read after that point.
- Move the contents to a different bucket with restrictive settings and leave the original bucket in place but empty, because the addresses that were reading it will then receive nothing and the situation resolves itself without an abrupt configuration change that might break a legitimate consumer.