SCS-C02 exam dumps

SCS-C02 practice question 10 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 10

Select 3

An e-commerce company is using an Amazon S3 bucket to store sensitive customer data. The security team wants to ensure that the data in the bucket is encrypted at all times and that the company maintains control over the encryption keys. Additionally, they need to audit access to the bucket and ensure that unauthorized access attempts are detected. Which combination of steps should the company take to meet these requirements?

  1. A

    Enable server-side encryption with AWS Key Management Service (SSE-KMS) and use a customer-managed KMS key.

  2. B

    Enable Amazon S3 bucket logging to track all access requests.

  3. C

    Enable AWS CloudTrail logging for S3 data events.

  4. D

    Use Amazon S3 server-side encryption with Amazon S3-managed keys (SSE-S3).

  5. E

    Enable Amazon Macie to monitor and classify sensitive data.

Show answer and explanation

Correct answers: A, C, E

Explanation

To meet the requirements, the company must first ensure data encryption with control over the encryption keys, which is achieved by using SSE-KMS with a customer-managed KMS key. AWS CloudTrail logging for S3 data events is essential for auditing access and identifying unauthorized access attempts. Additionally, Amazon Macie enhances security by detecting sensitive data and monitoring for anomalies, which helps fulfill the detection requirement. Bucket logging and SSE-S3 were not selected as they do not fully meet the stated requirements.

  • A. Correct.

    Correct. Enabling SSE-KMS with a customer-managed KMS key ensures that data is encrypted and the company retains control over the encryption keys.

  • B. Incorrect.

    Incorrect. While bucket logging can track access requests, it is not sufficient for auditing or detecting unauthorized access attempts compared to CloudTrail.

  • C. Correct.

    Correct. AWS CloudTrail data event logging for S3 can monitor and log all actions performed on the bucket, providing a detailed audit trail.

  • D. Incorrect.

    Incorrect. While SSE-S3 encrypts data, it does not provide the same level of key control as customer-managed KMS keys.

  • E. Correct.

    Correct. Amazon Macie helps detect sensitive data and monitor for anomalies, aiding in the detection of unauthorized access attempts.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam