SCS-C02 exam dumps

SCS-C02 practice question 352 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 352

Select 2

You are designing a data storage solution for a healthcare application that must comply with HIPAA regulations. The application stores sensitive patient data in Amazon S3. To ensure confidentiality and integrity for data at rest, which set of actions should you implement?

  1. A

    Enable server-side encryption with AWS Key Management Service (SSE-KMS) on the S3 bucket.

  2. B

    Use Amazon S3 Object Lock to enable write-once-read-many (WORM) protection on the bucket.

  3. C

    Enable default bucket encryption and use customer-managed keys (CMKs) in AWS KMS.

  4. D

    Implement a bucket policy to enforce the use of HTTPS for all data transfer operations.

  5. E

    Enable S3 Versioning to retain previous versions of objects in the bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure confidentiality and integrity for data at rest in Amazon S3, you should enable server-side encryption, preferably with AWS KMS, and use customer-managed keys for more control over encryption operations. These configurations ensure compliance with regulations like HIPAA by protecting sensitive data against unauthorized access or tampering. Other options, like enforcing HTTPS or enabling versioning, address different aspects of data security but are not directly related to encryption or integrity for data at rest.

  • A. Correct.

    Correct. Enabling server-side encryption with AWS KMS ensures that all data stored in the S3 bucket is encrypted at rest, providing confidentiality and integrity.

  • B. Incorrect.

    Incorrect. Amazon S3 Object Lock is useful for preventing object deletion or modification, but it does not directly ensure encryption or integrity for data at rest.

  • C. Correct.

    Correct. Enabling default bucket encryption with customer-managed keys gives you full control over encryption and key management, ensuring confidentiality and integrity for data at rest.

  • D. Incorrect.

    Incorrect. Enforcing HTTPS ensures data in transit is encrypted but does not address encryption or integrity for data at rest.

  • E. Incorrect.

    Incorrect. While enabling S3 Versioning can help retain previous versions of objects, it does not directly ensure confidentiality or integrity for data at rest.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam