SCS-C02 exam dumps

SCS-C02 practice question 167 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 167

Select 2

Your organization is using an Amazon S3 bucket to store sensitive customer data. You have been tasked with ensuring that the bucket’s contents are encrypted and access is tightly controlled. Which combination of steps would BEST meet these requirements?

  1. A

    Enable server-side encryption with AWS Key Management Service (SSE-KMS) on the S3 bucket.

  2. B

    Configure an S3 bucket policy that explicitly denies access to all users except specific IAM roles.

  3. C

    Enable S3 versioning to track changes to objects in the bucket.

  4. D

    Use Amazon Macie to monitor and classify sensitive data in the bucket.

  5. E

    Enable public-read permissions on the bucket for faster access to objects.

Show answer and explanation

Correct answers: A, B

Explanation

To secure sensitive customer data in an S3 bucket, encryption and strict access control are essential. Enabling SSE-KMS ensures encryption at rest, while configuring a bucket policy to deny unauthorized access ensures that only approved IAM roles can interact with the bucket. While other options, such as S3 versioning and Amazon Macie, are valuable for data management and monitoring, they do not directly address the core requirements of encryption and access control. Public-read permissions, on the other hand, would compromise security and should be avoided.

  • A. Correct.

    Enabling server-side encryption with AWS Key Management Service (SSE-KMS) ensures that all data stored in the bucket is encrypted. SSE-KMS provides a higher level of control, including audit logging and the ability to manage encryption keys.

  • B. Correct.

    Configuring an S3 bucket policy that explicitly denies access to all users except specific IAM roles ensures that only authorized identities can access the bucket. This is critical for controlling access to sensitive data.

  • C. Incorrect.

    Enabling S3 versioning helps track changes to objects in the bucket, but it does not directly address encryption or access control requirements.

  • D. Incorrect.

    Using Amazon Macie is useful for monitoring and classifying sensitive data, but it does not encrypt data or directly control access. It is more of a monitoring and compliance tool.

  • E. Incorrect.

    Enabling public-read permissions on the bucket would expose the data to unauthorized access and is not recommended for sensitive data.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam