DOP-C02 exam dumps

DOP-C02 practice question 409 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 409

Select 3

Your team has identified several security issues in your AWS environment. These include an S3 bucket with public read access enabled, AWS access keys embedded in your source code repository, and web traffic to your application being transmitted over HTTP. Which of the following actions should you take to mitigate these security threats?

  1. A

    Configure the S3 bucket to block public access and enable server-side encryption.

  2. B

    Rotate the exposed AWS access keys and remove them from the source code repository.

  3. C

    Ensure the application redirects HTTP traffic to HTTPS using an Application Load Balancer.

  4. D

    Enable versioning on the S3 bucket to prevent data loss.

  5. E

    Set up AWS WAF (Web Application Firewall) to protect the application from common web exploits.

Show answer and explanation

Correct answers: A, B, C

Explanation

The identified security threats include public S3 bucket access, exposed AWS access keys, and insecure HTTP traffic. To mitigate these, you must block public access and enable encryption on the S3 bucket, rotate and remove the exposed credentials, and ensure HTTP traffic is redirected to HTTPS. While AWS WAF and S3 versioning are valuable features, they do not directly address these specific threats.

  • A. Correct.

    Correct: Blocking public access to the S3 bucket prevents unauthorized access, and enabling server-side encryption ensures the data is encrypted at rest. These steps directly address the identified security issue.

  • B. Correct.

    Correct: Rotating the AWS access keys and removing them from the source code repository eliminates the risk of unauthorized access caused by exposed credentials.

  • C. Correct.

    Correct: Redirecting HTTP traffic to HTTPS ensures that data in transit is encrypted, mitigating the risk of insecure web traffic.

  • D. Incorrect.

    Incorrect: While enabling versioning on the S3 bucket is a good practice for data recovery, it does not address the identified security threats of public access or lack of encryption.

  • E. Incorrect.

    Incorrect: AWS WAF is used to protect against web application threats, such as SQL injection or cross-site scripting, but it does not address the specific issues of public S3 buckets, exposed access keys, or insecure HTTP traffic.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam