SCS-C02 exam dumps

SCS-C02 practice question 322 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 322

Select 3

Your organization stores sensitive financial data in an Amazon S3 bucket. To comply with regulatory requirements, you need to ensure that all objects in the bucket are encrypted, both at rest and during transit. Additionally, the solution must prevent any accidental uploads of unencrypted data into the bucket. Which combination of actions should you take to meet these requirements?

  1. A

    Enable default encryption on the S3 bucket using an AWS Key Management Service (AWS KMS) key.

  2. B

    Configure an S3 bucket policy to deny any PUT requests that do not include the 'x-amz-server-side-encryption' header.

  3. C

    Enable S3 Transfer Acceleration to ensure all data is encrypted during upload.

  4. D

    Use an S3 lifecycle policy to automatically encrypt existing unencrypted objects in the bucket.

  5. E

    Enable Secure Socket Layer (SSL) enforcement on the bucket by requiring HTTPS for requests.

Show answer and explanation

Correct answers: A, B, E

Explanation

To meet the requirements of encrypting data at rest and in transit, and preventing accidental uploads of unencrypted data, you should enable default encryption, enforce HTTPS, and use a bucket policy to deny unencrypted uploads. Default encryption ensures all new objects are encrypted at rest, HTTPS secures data in transit, and the bucket policy prevents unencrypted objects from being uploaded.

  • A. Correct.

    Correct. Enabling default encryption ensures that all new objects uploaded to the bucket are automatically encrypted at rest using the specified AWS KMS key or S3-managed encryption.

  • B. Correct.

    Correct. Configuring a bucket policy to deny PUT requests without the 'x-amz-server-side-encryption' header ensures that unencrypted objects cannot be uploaded to the bucket.

  • C. Incorrect.

    Incorrect. S3 Transfer Acceleration improves upload speed from geographically distant locations but does not guarantee encryption during transit. Encryption during transit is achieved by enforcing HTTPS.

  • D. Incorrect.

    Incorrect. S3 lifecycle policies manage object lifecycle transitions (e.g., moving to Glacier) but cannot apply encryption to existing unencrypted objects. Manual re-encryption or a separate tool would be necessary.

  • E. Correct.

    Correct. Enforcing SSL (HTTPS) ensures that all data in transit to and from the S3 bucket is encrypted, thereby securing data during transfer.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam