SAP-C02 exam dumps

SAP-C02 practice question 155 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 155

Select 4

A financial services company is migrating its on-premises data analytics platform to AWS. The platform processes sensitive customer data, and the company must meet compliance requirements such as GDPR and PCI DSS. They want to implement a solution that ensures data encryption at rest and in transit, minimizes the risk of unauthorized access, and provides detailed auditing capabilities for compliance purposes. Which combination of services and features should the company use?

  1. A

    AWS Key Management Service (KMS) for encryption at rest and AWS Certificate Manager (ACM) for encryption in transit

  2. B

    Amazon Macie for sensitive data discovery and monitoring

  3. C

    AWS CloudTrail with log file integrity validation for auditing API calls

  4. D

    Amazon S3 with default bucket policies to restrict access

  5. E

    AWS Secrets Manager to manage API keys and sensitive credentials

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To meet compliance requirements such as GDPR and PCI DSS, the company must implement encryption at rest and in transit, sensitive data discovery, auditing, and secure management of credentials. AWS KMS and ACM address encryption, Amazon Macie ensures sensitive data is monitored, AWS CloudTrail supports auditing, and Secrets Manager ensures secure handling of sensitive credentials. S3 bucket policies alone do not provide encryption or auditing capabilities, so they are insufficient in this case.

  • A. Correct.

    Correct: AWS KMS provides centralized key management for encrypting data at rest, while ACM simplifies the management of SSL/TLS certificates for encryption in transit.

  • B. Correct.

    Correct: Amazon Macie helps identify and monitor sensitive data in the environment, aligning with GDPR and PCI DSS requirements.

  • C. Correct.

    Correct: AWS CloudTrail ensures compliance by auditing API calls and log file integrity validation detects any tampering with logs.

  • D. Incorrect.

    Incorrect: While Amazon S3 bucket policies can restrict access, they do not provide encryption or auditing directly. Additional configurations would be needed for encryption and compliance.

  • E. Correct.

    Correct: AWS Secrets Manager securely manages sensitive information such as API keys, ensuring they are not hardcoded or exposed.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam