Lab 2 · Public Bucket with Sensitive Data
Confirm a public sensitive bucket in DAC and remediate it from the UI with Block Public Access.
Scenario tie-in
Block Public Access was turned off and an anonymous
s3:GetObject policy attached.2.1 Find it
- Reports → Overexposed Resources, filter AWS.
- Look for public + sensitive.
- Open a resource → Sensitive data + Access tabs; View full page.
2.2 Remediate (automated)
- Actionable → Limit External Access facet.
- Select bucket(s) → Run Action → Enable Public Access Block, run now.
Done when
The bucket no longer shows as publicly exposed in DAC.

