SCS-C02 exam dumps

SCS-C02 practice question 305 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 305

Select 2

You are a Security Engineer at a company that uses an S3 bucket to store sensitive customer data. You have been asked to ensure that the bucket cannot be accidentally made public by anyone in the organization. What steps should you take to achieve this?

  1. A

    Enable S3 Block Public Access at the bucket level.

  2. B

    Attach an IAM policy to all users that denies the ability to modify bucket permissions.

  3. C

    Enable S3 Block Public Access at the account level.

  4. D

    Use an S3 bucket policy to explicitly deny public access.

  5. E

    Enable AWS Config rules to monitor bucket ACL changes.

Show answer and explanation

Correct answers: A, C

Explanation

The most effective way to ensure an S3 bucket cannot be accidentally made public is to use S3 Block Public Access, as it automatically prevents public access regardless of bucket policies or ACLs. Enabling it at the bucket level addresses the specific bucket, while enabling it at the account level provides comprehensive protection across all buckets. Other options, such as IAM policies or AWS Config rules, are supplementary and either not as robust or do not directly block public access.

  • A. Correct.

    Enabling S3 Block Public Access at the bucket level ensures that public access to the specific S3 bucket is blocked, regardless of bucket policies or ACLs. This is an appropriate and effective method to prevent accidental public exposure of sensitive data.

  • B. Incorrect.

    Attaching an IAM policy to users denying permission to modify bucket permissions is not a scalable or practical solution, as it may interfere with legitimate administrative tasks and does not directly address the issue of blocking public access.

  • C. Correct.

    Enabling S3 Block Public Access at the account level ensures that no S3 bucket in the entire AWS account can be made public, which is a stronger and more comprehensive approach to prevent accidental public exposure.

  • D. Incorrect.

    Using an S3 bucket policy to explicitly deny public access could work, but it is less flexible and not as robust as using S3 Block Public Access, which is specifically designed for this purpose.

  • E. Incorrect.

    Enabling AWS Config rules to monitor bucket ACL changes is useful for detecting configuration changes, but it does not actively prevent the bucket from being made public.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam