AWS Certified DevOps Engineer - Professional (DOP-C02) Practice Question BankPracticeTrial (no sign-up)

Question 1 of 10Security and Compliance

The organization wants a preventive control that blocks public S3 access even if a workload administrator later adds a permissive bucket policy or ACL. Which control should be applied centrally?