passdrill
AWS SAA-C03 · S3 & Storage · Card 029/030 medium

A developer creates a brand-new S3 bucket in 2026 without changing any default settings, then has another AWS account upload an object to it using a custom ACL that attempts to grant a third account read access. What happens, given the bucket's default Object Ownership setting?

  1. The upload succeeds and the third account gains read access exactly as the ACL specified
  2. The upload succeeds, but only the bucket owner can read the object because ACLs are silently ignored
  3. The upload fails, because the default Bucket owner enforced setting disables ACLs and rejects PUT requests that specify one other than bucket-owner-full-control
  4. The upload succeeds only if the uploading account first disables S3 Block Public Access
Next card → Shuffle