SAP-C02 exam dumps

SAP-C02 practice question 618 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 618

Select 2

An e-commerce company is running a globally distributed application on AWS. The application uses Amazon S3 for static content, Amazon RDS for storing transactional data, and Amazon CloudFront for content distribution. During a recent audit, it was identified that sensitive customer data is being inadvertently exposed through the S3 bucket. The company wants to ensure that sensitive data is protected and access is restricted to only authorized users. Which combination of actions should you take to address this issue?

  1. A

    Enable S3 bucket policies to restrict access by IP address and AWS IAM roles.

  2. B

    Enable server-side encryption on the S3 bucket and enforce the use of S3-managed keys (SSE-S3).

  3. C

    Use AWS WAF to filter and block unauthorized access to the S3 bucket.

  4. D

    Enable Amazon S3 Block Public Access settings for the bucket.

  5. E

    Set up an Amazon CloudWatch alarm to monitor unauthorized access attempts to the S3 bucket.

Show answer and explanation

Correct answers: A, D

Explanation

To secure sensitive data in Amazon S3, you need to ensure that public access is blocked and that access is restricted to authorized users. Enabling S3 bucket policies allows fine-grained control over who can access the bucket, while Amazon S3 Block Public Access prevents the bucket from being publicly accessible. Server-side encryption, monitoring, and WAF are valuable but do not directly address the root cause of sensitive data exposure in this scenario.

  • A. Correct.

    S3 bucket policies can be used to restrict access to specific users, IP ranges, or AWS IAM roles. This is a best practice for securing S3 buckets and ensuring only authorized users can access sensitive data.

  • B. Incorrect.

    Server-side encryption (SSE-S3) ensures data is encrypted at rest but does not prevent unauthorized access to the bucket itself. While encryption is important, it does not address the issue of inadvertently exposed data.

  • C. Incorrect.

    AWS WAF is not designed for protecting S3 buckets. It is used for filtering and blocking web requests to services like CloudFront and Application Load Balancers.

  • D. Correct.

    Enabling Amazon S3 Block Public Access settings prevents any public access to the bucket and is a critical step in securing sensitive data to avoid inadvertent exposure.

  • E. Incorrect.

    Setting up a CloudWatch alarm can help monitor unauthorized access attempts, but it does not prevent the exposure of sensitive data or restrict access proactively.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam