DOP-C02 exam dumps

DOP-C02 practice question 410 of 411

AWS Certified DevOps Engineer - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

DOP-C02 Question 410

Select 3

Your organization has detected that an Amazon S3 bucket containing sensitive information was inadvertently made public. To mitigate this type of security issue and prevent it from happening in the future, which combination of actions should you take?

  1. A

    Enable S3 Block Public Access settings at the account level.

  2. B

    Use AWS Config rules to identify publicly accessible S3 buckets.

  3. C

    Apply an IAM policy to explicitly allow public access to the bucket.

  4. D

    Enable server-side encryption with an AWS-managed key (SSE-S3) for the bucket.

  5. E

    Set up an Amazon CloudWatch alarm to monitor S3 bucket access patterns.

Show answer and explanation

Correct answers: A, B, D

Explanation

To address the risk of sensitive information being exposed in publicly accessible S3 buckets, it is essential to prevent public access at the account or bucket level using S3 Block Public Access settings. Continuous monitoring with AWS Config rules helps identify and correct such misconfigurations. Adding server-side encryption ensures that sensitive data is protected at rest, even if it is accessed by unauthorized entities. These steps together form a robust approach to mitigate this type of security threat.

  • A. Correct.

    Enabling S3 Block Public Access at the account level prevents accidental public exposure of any bucket in the account. This is a critical step in mitigating such risks.

  • B. Correct.

    Using AWS Config rules allows you to continuously monitor your AWS environment for publicly accessible S3 buckets and take corrective actions.

  • C. Incorrect.

    Applying an IAM policy to explicitly allow public access to the bucket would further expose the sensitive data, which is the opposite of mitigating the issue.

  • D. Correct.

    Enabling server-side encryption ensures that data is encrypted at rest, adding an additional layer of protection for sensitive information in case of unauthorized access.

  • E. Incorrect.

    While monitoring access patterns with Amazon CloudWatch can be useful for detecting anomalies, it does not directly prevent or mitigate public exposure of S3 buckets.

Timed practice exam

Take a DOP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam