SCS-C02 exam dumps

SCS-C02 practice question 187 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 187

Select 3

You are managing a web application hosted on Amazon CloudFront with an S3 bucket as the origin. The application handles sensitive user data and must comply with strict security requirements. How can you design security controls to ensure that only CloudFront can access your S3 bucket while also protecting the application from malicious traffic?

  1. A

    Configure an S3 bucket policy to allow access only from specific CloudFront origin access identities (OAIs) or origin access controls (OACs).

  2. B

    Enable AWS WAF on the CloudFront distribution to filter out malicious traffic based on IP, geographic location, or request patterns.

  3. C

    Set the S3 bucket to 'public-read' so CloudFront can access it without restrictions.

  4. D

    Use field-level encryption in CloudFront to protect sensitive data before forwarding it to the origin.

  5. E

    Enable versioning on the S3 bucket to ensure that malicious traffic does not overwrite existing data.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure edge services like CloudFront and an S3 origin, you should use a layered security approach. Configuring an S3 bucket policy with OAIs or OACs ensures that only CloudFront can access the bucket. Adding AWS WAF to the CloudFront distribution helps in filtering malicious traffic before it reaches the application. Field-level encryption adds an additional layer of security for sensitive data transmitted through the edge. Together, these measures protect the application and its data while maintaining compliance with security requirements.

  • A. Correct.

    Correct. Configuring an S3 bucket policy to allow access only from specific CloudFront origin access identities (OAIs) or origin access controls (OACs) ensures that only CloudFront can retrieve objects from the bucket, protecting against unauthorized access.

  • B. Correct.

    Correct. AWS WAF can be used to filter out malicious traffic at the edge before it reaches your application, ensuring better security for your web application.

  • C. Incorrect.

    Incorrect. Setting the S3 bucket to 'public-read' would expose it to the internet, violating security best practices and increasing the risk of unauthorized access.

  • D. Correct.

    Correct. Field-level encryption in CloudFront allows sensitive data to be encrypted at the edge, protecting it from exposure during transmission to the origin.

  • E. Incorrect.

    Incorrect. While enabling versioning on the S3 bucket is useful for data recovery, it does not directly address the issue of securing access or filtering malicious traffic.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam