# Supplied case: cross-account S3 read investigation

All identifiers are fictional. Do not run commands against these values.

## Report

At 10:15 UTC, the data owner asks: “Can vendor account `222222222222` read
`s3://nw-private-reports/reports/quarter.csv`, and did it read the object?”

## Resource policy excerpt captured at 10:20 UTC

```json
{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "VendorReadApprovedPrefix",
    "Effect": "Allow",
    "Principal": {"AWS": "arn:aws:iam::222222222222:role/ReportReader"},
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::nw-private-reports/reports/*",
    "Condition": {
      "StringEquals": {
        "aws:PrincipalOrgID": "o-examplevendor",
        "aws:SourceVpce": "vpce-0example"
      },
      "Bool": {"aws:SecureTransport": "true"}
    }
  }]
}
```

The bucket uses SSE-KMS with a customer-managed key. The key policy and grants are
not included in the first evidence package. S3 Block Public Access is enabled.
That setting does not automatically block this named-principal grant.

## Access Analyzer extract

- Analyzer type: external access; account is the zone of trust.
- Finding status: `ACTIVE`; resource: the bucket; principal: vendor role.
- Finding says the named external account may receive `s3:GetObject` under the
  listed organization, endpoint and TLS conditions.
- The analyzer has no evidence about policies, SCPs or role sessions in the vendor
  account and does not prove that a request occurred.

## Simulator extract

An operator simulated the vendor role and `s3:GetObject` but did **not** supply the
bucket policy, `aws:PrincipalOrgID`, `aws:SourceVpce`, TLS context, an SCP, an STS
session policy, an RCP or the KMS key policy. The result was `implicitDeny`.

This result is incomplete, not proof that live access is denied.

## CloudTrail extract

Event history in `ap-south-1` contains an `AssumeRole` management event at 10:02
UTC. The investigator finds no `GetObject` event in Event history. The trail's
advanced event selectors were not inspected, and S3 object operations are data
events rather than management events.

This absence is not proof that the object was not read.

## Learner task

Separate and answer:

1. What access path does the resource policy make possible?
2. Which caller-side, resource-side, condition and KMS evidence is missing?
3. Why does the simulation not reproduce the live request context?
4. Which CloudTrail source/selectors, accounts, Regions and times must be searched?
5. What remediation or exception decision is justified only after those facts?
