SAA-C03 exam dumps

SAA-C03 practice question 66 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 66

Select 2

A company stores sensitive customer data in an Amazon S3 bucket. The company must ensure the data is encrypted at rest and that only specific IAM roles are permitted to access the bucket. Which combination of actions should the Solutions Architect recommend to achieve this?

  1. A

    Enable server-side encryption with Amazon S3-managed keys (SSE-S3) for the bucket.

  2. B

    Use an S3 bucket policy to explicitly deny access to all users except those with the specified IAM roles.

  3. C

    Enable versioning on the S3 bucket to track changes to objects.

  4. D

    Configure server-side encryption with AWS Key Management Service (SSE-KMS) and use a customer-managed key.

  5. E

    Use an S3 Access Control List (ACL) to grant access only to the specified IAM roles.

Show answer and explanation

Correct answers: B, D

Explanation

To meet the requirements of encrypting data at rest and restricting access to specific IAM roles, enabling SSE-KMS with a customer-managed key ensures proper encryption with fine-grained control over key permissions. Additionally, using an S3 bucket policy to deny access to unauthorized users ensures that only specific IAM roles can access the data. These two measures together provide robust security controls for sensitive data stored in S3.

  • A. Incorrect.

    Enabling SSE-S3 ensures encryption at rest using S3-managed keys, but it doesn't allow fine-grained control over key management and permissions.

  • B. Correct.

    Using an S3 bucket policy to explicitly deny access to all users except those with specific IAM roles ensures that only authorized entities can access the bucket. It is a key security control for restricting access.

  • C. Incorrect.

    Enabling versioning helps track changes to objects but does not directly address encryption or access control requirements.

  • D. Correct.

    Configuring SSE-KMS with a customer-managed key provides encryption at rest and allows fine-grained control over key usage and permissions, meeting the encryption requirement.

  • E. Incorrect.

    S3 ACLs provide basic access controls but are less flexible and granular compared to bucket policies and IAM roles. They are not recommended for implementing complex security controls.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam