SAP-C02 exam dumps

SAP-C02 practice question 41 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 41

Select 3

A financial institution is migrating its core banking application to AWS. The application processes highly sensitive customer data and must comply with strict regulatory requirements, including data encryption in transit and at rest, access control, and audit logging. As part of the solution design, which combination of AWS security controls should you prescribe to meet these requirements?

  1. A

    Enable AWS Key Management Service (KMS) to manage encryption keys and encrypt data at rest.

  2. B

    Use AWS WAF (Web Application Firewall) to encrypt data in transit between application components.

  3. C

    Configure Amazon CloudTrail to capture API activity and enable logs for auditing purposes.

  4. D

    Enforce IAM policies to restrict access to resources based on the principle of least privilege.

  5. E

    Use AWS Shield Advanced to protect against Distributed Denial of Service (DDoS) attacks.

Show answer and explanation

Correct answers: A, C, D

Explanation

To meet the security and compliance requirements of a financial institution, it is necessary to prescribe controls that address encryption of data at rest, audit logging, and access control. AWS Key Management Service (KMS) ensures data at rest is encrypted, Amazon CloudTrail provides the necessary audit logs, and IAM policies ensure least privilege access control. While AWS WAF and AWS Shield Advanced are valuable security services, they do not directly address the specific requirements outlined in the scenario.

  • A. Correct.

    This is correct because AWS KMS can be used to manage encryption keys and ensure data at rest is encrypted, which is a key compliance requirement for financial institutions.

  • B. Incorrect.

    This is incorrect because AWS WAF is primarily used to protect web applications from common threats like SQL injection or cross-site scripting, not for encrypting data in transit.

  • C. Correct.

    This is correct because Amazon CloudTrail captures API activity for AWS resources, enabling audit logging, which is essential for compliance and monitoring.

  • D. Correct.

    This is correct because implementing IAM policies based on the principle of least privilege ensures that only authorized users and applications can access sensitive resources.

  • E. Incorrect.

    This is incorrect because AWS Shield Advanced is a DDoS protection service and does not address encryption, access control, or audit logging requirements directly.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam