SAA-C03 exam dumps

SAA-C03 practice question 67 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 67

Select 3

A company is hosting sensitive financial data in an Amazon S3 bucket. The company requires that this data must be encrypted when stored, and only specific employees within the organization should have access to it. Additionally, access to the bucket should be logged for auditing purposes. What combination of controls should the company implement to meet these requirements?

  1. A

    Enable Server-Side Encryption with AWS Key Management Service (SSE-KMS) for the S3 bucket.

  2. B

    Configure an S3 bucket policy to allow public read access to the bucket.

  3. C

    Enable S3 server access logging or AWS CloudTrail logging for the bucket.

  4. D

    Use IAM policies to restrict access to the bucket to specific IAM users or roles.

  5. E

    Enable Transfer Acceleration for faster data uploads to the S3 bucket.

Show answer and explanation

Correct answers: A, C, D

Explanation

To secure sensitive financial data in an Amazon S3 bucket, encryption is required to protect the data at rest (achieved using SSE-KMS). Access must be restricted to specific employees, which can be implemented using IAM policies. Finally, access logs are essential for audit purposes, which can be enabled with S3 Server Access Logging or AWS CloudTrail. These controls together meet the company's security requirements.

  • A. Correct.

    This is correct. Server-Side Encryption with AWS Key Management Service (SSE-KMS) ensures that the data is encrypted when stored in the S3 bucket, meeting the company's requirement for encryption.

  • B. Incorrect.

    This is incorrect. Allowing public read access would expose the sensitive financial data to everyone on the internet, violating the security requirements.

  • C. Correct.

    This is correct. Enabling either S3 server access logging or AWS CloudTrail logging ensures that all access requests to the bucket are logged, which is necessary for auditing purposes.

  • D. Correct.

    This is correct. Using IAM policies to restrict access ensures that only specific employees can access the bucket, meeting the requirement for controlled access.

  • E. Incorrect.

    This is incorrect. Transfer Acceleration is used for improving upload speeds to S3 but does not address encryption, access control, or logging requirements.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam