SAP-C02 exam dumps

SAP-C02 practice question 43 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 43

Select 3

A financial services company is designing a highly secure web application that processes sensitive customer data. The solution must comply with strict regulatory requirements, including data encryption, least privilege access, and logging of all API interactions. As the Solutions Architect, which security controls should you recommend to meet these requirements?

  1. A

    Enable AWS Key Management Service (AWS KMS) to encrypt data at rest and AWS Certificate Manager (ACM) for data in transit.

  2. B

    Use IAM policies with least privilege access and enforce multi-factor authentication (MFA) for administrative users.

  3. C

    Configure Amazon CloudWatch Logs and AWS CloudTrail to monitor and record all API calls.

  4. D

    Deploy the application in a public subnet to allow global access and reduce latency for users worldwide.

  5. E

    Use AWS WAF (Web Application Firewall) to protect against common web exploits such as SQL injection and cross-site scripting.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the security and compliance requirements for sensitive customer data, encryption with AWS KMS and ACM ensures data protection at rest and in transit, least privilege access with IAM policies and MFA secures administrative access, and logging with AWS CloudTrail and CloudWatch Logs ensures visibility into API interactions. Deploying the application in a public subnet and using AWS WAF are not directly aligned with the task requirements.

  • A. Correct.

    Correct. Encrypting data at rest with AWS KMS and using ACM for secure data in transit ensures compliance with encryption requirements for sensitive data.

  • B. Correct.

    Correct. Using IAM policies with least privilege access and MFA for administrative users aligns with the principle of least privilege and enhances security.

  • C. Correct.

    Correct. AWS CloudTrail and Amazon CloudWatch Logs provide detailed logging and monitoring of API interactions, which is essential for compliance and audits.

  • D. Incorrect.

    Incorrect. Deploying the application in a public subnet does not align with security best practices for sensitive data as it exposes the application to potential external threats.

  • E. Incorrect.

    Incorrect. While AWS WAF can enhance security by mitigating web exploits, it does not directly address the requirements for encryption, least privilege access, or logging.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam