SCS-C02 exam dumps

SCS-C02 practice question 109 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 109

Select 2

An organization is using AWS S3 to store sensitive customer data. To comply with compliance requirements, they need to ensure that the data is encrypted at rest and prevent any accidental exposure of unencrypted objects. Which combination of measures should the organization implement to achieve this goal?

  1. A

    Enable S3 default encryption for the bucket to automatically encrypt all new objects.

  2. B

    Apply an S3 bucket policy that denies uploads of objects without encryption.

  3. C

    Enable S3 Object Lock to prevent modification or deletion of objects.

  4. D

    Use Amazon Macie to automatically classify sensitive data in the bucket.

  5. E

    Enable AWS KMS (Key Management Service) and use a customer-managed key for encryption.

Show answer and explanation

Correct answers: A, B

Explanation

To ensure compliance with encryption requirements for sensitive data, the organization should enable S3 default encryption to encrypt all new objects automatically. Additionally, applying a bucket policy to deny unencrypted uploads ensures that no objects are stored without encryption. While other options like using AWS KMS or Amazon Macie offer complementary functionality, they do not directly address the need to enforce encryption for all objects in the bucket.

  • A. Correct.

    Enabling S3 default encryption ensures that all newly uploaded objects are automatically encrypted at rest, meeting compliance requirements for data protection.

  • B. Correct.

    Applying an S3 bucket policy to deny uploads of unencrypted objects ensures that no unencrypted data can be stored in the bucket, preventing accidental exposure of unencrypted objects.

  • C. Incorrect.

    S3 Object Lock is designed for retention and immutability purposes, not specifically for enforcing encryption requirements.

  • D. Incorrect.

    Amazon Macie is a data classification service and does not provide encryption capabilities or enforce encryption policies.

  • E. Incorrect.

    Enabling AWS KMS and using a customer-managed key can help with encryption, but it does not enforce encryption for all objects unless combined with other measures like default encryption or bucket policies.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam