SCS-C02 exam dumps

SCS-C02 practice question 391 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 391

Select 2

Your organization is required to comply with government-mandated data retention standards that dictate retaining sensitive customer data for 7 years. You are tasked with ensuring that an Amazon S3 bucket used to store this data is configured to meet these requirements. Which of the following configurations should you implement to ensure compliance with the retention policy?

  1. A

    Enable S3 Object Lock with a Retention Period of 7 years in Compliance mode.

  2. B

    Use S3 Lifecycle rules to automatically delete objects older than 7 years.

  3. C

    Enable S3 Versioning and configure a lifecycle policy to retain non-current versions for 7 years.

  4. D

    Use S3 Object Lock with a Retention Period of 7 years in Governance mode.

  5. E

    Configure default encryption for the S3 bucket to ensure data is encrypted at rest.

Show answer and explanation

Correct answers: A, D

Explanation

To meet strict data retention standards, Amazon S3 Object Lock is the most appropriate solution. Compliance mode ensures immutability by preventing any object modifications or deletions during the retention period, even by administrators. Governance mode provides similar enforcement but allows authorized users with special permissions to make changes if necessary. Lifecycle rules and versioning are useful for data management but do not enforce strict retention policies. Encryption, while important for data security, does not address retention standards.

  • A. Correct.

    This is a correct option. S3 Object Lock in Compliance mode ensures that no one, not even administrators, can overwrite or delete objects during the retention period, which aligns with strict data retention policies.

  • B. Incorrect.

    This option is incorrect. While S3 Lifecycle rules can help manage object expiration, they do not enforce a strict retention policy to prevent deletion or modification during a mandated retention period.

  • C. Incorrect.

    This option is incorrect. S3 Versioning and lifecycle policies for non-current versions do not enforce immutability or compliance with regulatory retention requirements.

  • D. Correct.

    This is a correct option. S3 Object Lock in Governance mode allows for retention enforcement but requires elevated permissions to override, which can still meet compliance needs if properly managed.

  • E. Incorrect.

    This option is incorrect. While enabling encryption ensures data is secure, it does not address the retention enforcement required by the data retention policy.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam