SCS-C02 exam dumps

SCS-C02 practice question 111 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 111

Select 3

An organization is using Amazon S3 to store sensitive customer data. The security team has identified a requirement to ensure that data in S3 is encrypted at rest and that the encryption keys are managed using AWS Key Management Service (KMS). Additionally, they want to prevent accidental disabling or deletion of the KMS keys. Which combination of steps should the security team take to meet these requirements?

  1. A

    Enable default encryption on the S3 bucket using an AWS KMS key.

  2. B

    Use S3 bucket policies to require that all uploads use server-side encryption with AWS KMS.

  3. C

    Create a KMS key policy that prevents the key from being disabled or deleted by unauthorized users.

  4. D

    Enable S3 Object Lock on the bucket to prevent key deletion.

  5. E

    Use AWS Secrets Manager to rotate the KMS key automatically.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the requirements of encrypting data at rest in S3 and managing encryption keys using AWS KMS, the security team should enable default encryption on the bucket with an AWS KMS key and enforce encryption via bucket policies. Additionally, to prevent accidental disabling or deletion of the KMS key, creating a restrictive KMS key policy is essential. Options like S3 Object Lock and AWS Secrets Manager do not address the requirements related to KMS key management or encryption enforcement.

  • A. Correct.

    Enabling default encryption on the S3 bucket using an AWS KMS key ensures that all objects stored in the bucket are encrypted with the specified KMS key, meeting the encryption-at-rest requirement.

  • B. Correct.

    Using S3 bucket policies to enforce server-side encryption with AWS KMS ensures that only encrypted objects are allowed to be uploaded to the bucket, enhancing security.

  • C. Correct.

    Creating a KMS key policy to prevent unauthorized users from disabling or deleting the KMS key ensures that the encryption key remains available and operational, reducing the risk of data exposure.

  • D. Incorrect.

    S3 Object Lock is used to enforce retention and legal holds on objects stored in S3, but it does not prevent accidental or unauthorized deletion of KMS keys.

  • E. Incorrect.

    AWS Secrets Manager is used for managing and rotating secrets, such as database credentials or API keys, but it is not used for rotating or managing AWS KMS keys.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam