DOP-C02 exam dumps

DOP-C02 practice question 373 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 373

Select 3

You are managing an AWS environment for a financial services company that requires strict adherence to compliance regulations, including encryption of sensitive data. To ensure compliance, you have been tasked with automating the implementation of security controls for S3 buckets to enforce encryption and logging. Which combination of actions would achieve this requirement?

  1. A

    Use an S3 Bucket Policy to deny uploads of objects that do not have server-side encryption enabled.

  2. B

    Enable S3 Server Access Logging and direct the logs to a centralized logging bucket.

  3. C

    Use AWS Config to create a custom rule that checks for S3 buckets without default encryption enabled.

  4. D

    Implement an AWS Lambda function triggered by S3 events to encrypt unencrypted objects after they are uploaded.

  5. E

    Enable S3 Intelligent-Tiering to ensure cost optimization and data protection.

Show answer and explanation

Correct answers: A, B, C

Explanation

Automating security controls and data protection in S3 involves enforcing encryption policies, implementing logging for auditing, and leveraging AWS Config for compliance monitoring. Using proactive measures such as Bucket Policies and AWS Config rules ensures compliance and reduces manual intervention. Reactive measures like using Lambda to encrypt uploaded objects are less efficient and not aligned with best practices for automating security controls.

  • A. Correct.

    Correct: An S3 Bucket Policy can enforce encryption by rejecting uploads of objects without server-side encryption, ensuring compliance automatically.

  • B. Correct.

    Correct: Enabling S3 Server Access Logging and directing logs to a centralized bucket provides detailed records of access and actions, which is critical for compliance and auditing.

  • C. Correct.

    Correct: AWS Config can be used to create custom compliance rules, such as checking for S3 buckets without default encryption, and can trigger remediation actions automatically.

  • D. Incorrect.

    Incorrect: While an AWS Lambda function could theoretically encrypt objects after upload, this approach is reactive and not a recommended best practice for ensuring compliance proactively.

  • E. Incorrect.

    Incorrect: S3 Intelligent-Tiering is a storage class designed for cost optimization and managing data access patterns, but it does not enforce encryption or apply security controls.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam