SCS-C02 exam dumps

SCS-C02 practice question 211 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 211

Select 3

Your organization uses an Amazon S3 bucket to store sensitive customer data. The security team has recently identified the need to ensure that the data is encrypted at rest and that access is logged for auditing purposes. Additionally, any accidental public access to the bucket must be prevented. Which combination of actions will meet these requirements?

  1. A

    Enable server-side encryption (SSE) on the bucket using AWS Key Management Service (KMS) keys.

  2. B

    Enable the S3 Block Public Access settings for the bucket.

  3. C

    Enable Amazon S3 server access logging and configure the logs to be stored in another S3 bucket.

  4. D

    Use an S3 bucket policy to allow all users in the organization full access to the bucket.

  5. E

    Enable Cross-Region Replication to replicate the bucket data to another region for redundancy.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the security requirements, you must ensure encryption at rest, prevent public access, and enable logging for auditing. Server-side encryption (SSE) with AWS KMS provides strong encryption for sensitive data. Enabling S3 Block Public Access ensures no accidental public access occurs, and enabling S3 server access logging provides valuable access records for auditing purposes. These steps collectively fulfill the security team's requirements.

  • A. Correct.

    Correct. Enabling server-side encryption (SSE) with AWS KMS ensures that the data stored in the bucket is encrypted at rest, meeting the encryption requirement.

  • B. Correct.

    Correct. Enabling S3 Block Public Access settings prevents any accidental public access to the bucket, addressing the requirement to secure sensitive data.

  • C. Correct.

    Correct. Enabling S3 server access logging allows you to track access requests to the bucket and store logs for auditing purposes, fulfilling the auditing requirement.

  • D. Incorrect.

    Incorrect. Allowing all users in the organization full access to the bucket does not align with the requirement to secure sensitive customer data.

  • E. Incorrect.

    Incorrect. While Cross-Region Replication improves redundancy, it does not address encryption at rest, access logging, or preventing public access.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam