SCS-C02 exam dumps

SCS-C02 practice question 237 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 237

Select 3

A company is using Amazon S3 to store sensitive financial data. To meet compliance requirements, the company must ensure that this data is encrypted both at rest and in transit. Additionally, they need to monitor for any unencrypted objects and prevent future uploads of unencrypted objects. Which combination of solutions will meet these requirements?

  1. A

    Enable default encryption for the S3 bucket using an AWS Key Management Service (KMS) key.

  2. B

    Use an S3 bucket policy that denies uploads of objects without encryption.

  3. C

    Enable server access logging on the S3 bucket to monitor unencrypted objects.

  4. D

    Use AWS Config with the managed rule 's3-bucket-server-side-encryption-enabled' to detect unencrypted objects.

  5. E

    Enable S3 Transfer Acceleration to enforce encryption in transit.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the compliance requirements of encrypting data at rest and in transit, the company needs to ensure S3 default encryption is enabled and enforce encryption for future uploads using a bucket policy. Additionally, AWS Config can monitor and detect unencrypted objects. Server access logging and S3 Transfer Acceleration, while useful for other purposes, do not directly address the encryption requirements.

  • A. Correct.

    Correct: Enabling default encryption ensures that all objects stored in the S3 bucket are encrypted at rest using the specified encryption key.

  • B. Correct.

    Correct: An S3 bucket policy denying uploads without encryption ensures that all future objects uploaded to the bucket are encrypted.

  • C. Incorrect.

    Incorrect: Server access logging only provides logs of access requests and does not specifically monitor unencrypted objects.

  • D. Correct.

    Correct: AWS Config's managed rule 's3-bucket-server-side-encryption-enabled' helps detect buckets that do not have server-side encryption enabled, ensuring compliance with the encryption requirement.

  • E. Incorrect.

    Incorrect: S3 Transfer Acceleration improves upload speeds but does not enforce encryption for data in transit.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam