SAA-C03 exam dumps

SAA-C03 practice question 75 of 553

AWS Certified Solutions Architect - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAA-C03 Question 75

Select 3

Your organization recently adopted an AWS environment where sensitive business data is stored in Amazon S3. Compliance requirements mandate that access to this data must be tightly controlled, monitored, and audited. Which combination of solutions can help you meet these requirements?

  1. A

    Enable Amazon S3 Bucket Policies to define fine-grained access to specific objects and actions.

  2. B

    Turn on AWS CloudTrail to log all API activity related to the S3 buckets.

  3. C

    Use AWS Config to track changes to S3 bucket configurations and alert on non-compliance.

  4. D

    Enable S3 Versioning to retain multiple versions of objects for audit purposes.

  5. E

    Use IAM roles with inline policies to grant unrestricted access to the S3 bucket.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet compliance requirements for data access and governance in Amazon S3, you need a combination of access control, monitoring, and auditing solutions. S3 Bucket Policies provide fine-grained access control, CloudTrail enables monitoring of API activity, and AWS Config ensures that any changes to the S3 bucket's configuration are tracked and can trigger alerts for non-compliance. S3 Versioning and unrestricted IAM role policies are not suitable solutions for this scenario.

  • A. Correct.

    Amazon S3 Bucket Policies allow you to define fine-grained access control to the bucket and its objects. This is essential for restricting access to sensitive data.

  • B. Correct.

    AWS CloudTrail provides logging and monitoring of all API activity, helping you audit access to the S3 bucket.

  • C. Correct.

    AWS Config enables tracking of configuration changes to S3 buckets and can alert you when configurations become non-compliant with policies.

  • D. Incorrect.

    S3 Versioning is useful for retaining object versions but does not address access control or auditing requirements directly.

  • E. Incorrect.

    Granting unrestricted access to the S3 bucket using IAM roles with inline policies violates the requirement for tightly controlled access.

Timed practice exam

Take a SAA-C03 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam