SAA-C03 exam dumps

SAA-C03 practice question 64 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 64

Select 3

A company stores sensitive customer data in an Amazon S3 bucket. Due to regulatory requirements, they must ensure that the data is encrypted both at rest and in transit. Additionally, unauthorized access to the bucket should be prevented. Which combination of actions should the company take to meet these requirements?

  1. A

    Enable server-side encryption (SSE) with AWS Key Management Service (AWS KMS) for the S3 bucket.

  2. B

    Use an S3 bucket policy to restrict access to specific IAM roles and users.

  3. C

    Enable S3 Versioning to maintain a history of object changes.

  4. D

    Configure the bucket to force HTTPS connections using a bucket policy.

  5. E

    Use Amazon Macie to monitor and classify sensitive data in the bucket.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the regulatory requirements, the company must ensure encryption both at rest and in transit, and restrict unauthorized access. Enabling server-side encryption with AWS KMS ensures encryption at rest, while forcing HTTPS connections secures data in transit. Restricting access using an S3 bucket policy prevents unauthorized access to the sensitive customer data. While other options like enabling versioning or using Amazon Macie are valuable for other purposes, they do not directly address the specific requirements in this scenario.

  • A. Correct.

    Enabling server-side encryption with AWS KMS ensures that data is encrypted at rest, fulfilling the requirement for encryption of stored data.

  • B. Correct.

    Using an S3 bucket policy to restrict access ensures that only authorized IAM roles and users can access the bucket, meeting the requirement to prevent unauthorized access.

  • C. Incorrect.

    While enabling S3 Versioning is a good practice for data recovery and auditing, it does not address encryption or access control requirements.

  • D. Correct.

    Configuring the bucket to force HTTPS connections ensures that data is encrypted in transit, fulfilling the requirement for encryption during transmission.

  • E. Incorrect.

    Amazon Macie is useful for discovering and classifying sensitive data, but it does not directly address encryption or access control requirements for the S3 bucket.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam