SCS-C02 exam dumps

SCS-C02 practice question 35 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 35

Select 3

Your organization is using Amazon S3 to store sensitive customer data and must ensure that this data is encrypted both at rest and in transit. The security team also wants to minimize operational overhead by relying on AWS-managed encryption solutions. Which combination of measures should you implement to meet these requirements?

  1. A

    Enable server-side encryption with Amazon S3-managed keys (SSE-S3).

  2. B

    Configure server-side encryption with customer-provided keys (SSE-C).

  3. C

    Enable default bucket encryption using AWS Key Management Service (AWS KMS) keys (SSE-KMS).

  4. D

    Enforce HTTPS for all S3 bucket access using a bucket policy.

  5. E

    Enable client-side encryption with customer-managed keys.

Show answer and explanation

Correct answers: A, C, D

Explanation

To ensure the sensitive customer data is encrypted at rest and in transit while minimizing operational overhead, you should use AWS-managed encryption solutions such as SSE-S3 or SSE-KMS for encryption at rest and enforce HTTPS for secure data transmission. SSE-C and client-side encryption require key management by the customer, which increases operational overhead and does not meet the requirement for AWS-managed solutions.

  • A. Correct.

    Correct: SSE-S3 ensures that data is encrypted at rest using Amazon S3-managed keys, which minimizes operational overhead.

  • B. Incorrect.

    Incorrect: SSE-C requires you to manage and provide encryption keys yourself, which increases operational overhead and does not meet the requirement to use AWS-managed solutions.

  • C. Correct.

    Correct: SSE-KMS provides encryption at rest using AWS Key Management Service keys, which are managed by AWS and minimize operational complexity.

  • D. Correct.

    Correct: Enforcing HTTPS ensures that data in transit is encrypted, meeting the requirement to secure the data in transit.

  • E. Incorrect.

    Incorrect: Client-side encryption requires you to manage the encryption keys and process, which increases operational overhead and does not align with the requirement for AWS-managed solutions.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam