SCS-C02 exam dumps

SCS-C02 practice question 285 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 285

Select 2

An organization is using Amazon S3 to store sensitive data. The security team needs to ensure that the S3 bucket is protected against accidental public exposure, unauthorized access, and that all data is encrypted both in transit and at rest. Which of the following actions should the security team take to meet these requirements? (Select TWO)

  1. A

    Enable bucket versioning on the S3 bucket

  2. B

    Apply a bucket policy that denies public access to the bucket

  3. C

    Enable default encryption using an AWS Key Management Service (AWS KMS) key

  4. D

    Enable S3 Object Lock in compliance mode

  5. E

    Enable S3 Block Public Access settings at the bucket level

Show answer and explanation

Correct answers: B, C

Explanation

To secure the S3 bucket, the security team needs to prevent public exposure and ensure encryption at rest. Applying a bucket policy that denies public access (option 2) directly addresses the public exposure risk, while enabling default encryption with AWS KMS (option 3) ensures the data is encrypted at rest. While other options provide additional features or protections, they do not directly address the specific requirements in the scenario.

  • A. Incorrect.

    Enabling bucket versioning is useful for recovering older versions of objects but does not directly address public access, unauthorized access, or encryption requirements.

  • B. Correct.

    Applying a bucket policy that denies public access ensures that no one can accidentally make the bucket publicly accessible, addressing the requirement to prevent public exposure.

  • C. Correct.

    Enabling default encryption ensures that all objects stored in the S3 bucket are encrypted at rest, meeting the encryption requirement.

  • D. Incorrect.

    S3 Object Lock in compliance mode is used for data immutability and retention compliance but does not address unauthorized access or encryption.

  • E. Incorrect.

    Enabling S3 Block Public Access settings helps prevent public access, but applying a bucket policy (option 2) provides more granular control over access permissions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam