SAP-C02 exam dumps

SAP-C02 practice question 11 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 11

Select 2

Your company is migrating a legacy on-premises application to AWS. The application requires access to sensitive customer data stored in an Amazon S3 bucket. Compliance regulations mandate that all data access must be logged and encryption must be enforced for data at rest and in transit. Additionally, the application will run on an Amazon EC2 instance. What actions should you take to ensure compliance and secure the application’s access to the data?

  1. A

    Enable server-side encryption (SSE) with Amazon S3-managed keys (SSE-S3) for the bucket.

  2. B

    Create an IAM role with a policy granting the EC2 instance permissions to access only the specific S3 bucket and attach this role to the instance.

  3. C

    Require HTTPS for all communication between the EC2 instance and the S3 bucket by enforcing the use of S3 bucket policies.

  4. D

    Enable Amazon S3 Access Logs to monitor all access to the S3 bucket.

  5. E

    Use a pre-signed URL for the EC2 instance to access the S3 bucket instead of assigning an IAM role.

Show answer and explanation

Correct answers: B, C

Explanation

To meet the compliance requirements, encryption must be enforced for data both at rest and in transit, and access to the S3 bucket should be tightly controlled. Option 2 ensures that access is restricted to only the EC2 instance using an IAM role, while Option 3 enforces encryption in transit by mandating HTTPS communication. These measures collectively address the compliance requirements for secure access and data protection.

  • A. Incorrect.

    While enabling SSE with Amazon S3-managed keys (SSE-S3) ensures data is encrypted at rest, it does not address encryption in transit or access logging requirements. This option alone is insufficient for full compliance.

  • B. Correct.

    Attaching an IAM role with a tightly scoped policy to the EC2 instance ensures secure and least-privileged access to the S3 bucket, meeting compliance requirements for access control.

  • C. Correct.

    Enforcing HTTPS for communication ensures encryption in transit, which is a compliance requirement for securing sensitive data.

  • D. Incorrect.

    While enabling S3 Access Logs is good for monitoring, it is not sufficient to meet the encryption or secure access requirements.

  • E. Incorrect.

    Using a pre-signed URL does not provide the level of security needed for this scenario. Pre-signed URLs are typically used for temporary or client-side access and do not align with the long-term operational security of an application.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam