SCS-C02 exam dumps

SCS-C02 practice question 405 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 405

Select 3

An organization stores sensitive database credentials in AWS Systems Manager Parameter Store as SecureString parameters. To enhance security, they want to ensure that only specific IAM roles can access these parameters and that any unauthorized access attempts are logged. Which combination of actions should they take?

  1. A

    Attach an IAM policy to the specific roles allowing access to the SecureString parameters.

  2. B

    Enable AWS CloudTrail to monitor access to the Parameter Store.

  3. C

    Configure a resource-based policy on the SecureString parameters to restrict access.

  4. D

    Use a KMS key to encrypt the SecureString parameters and control access to the key.

  5. E

    Enable versioning for the SecureString parameters in Parameter Store.

Show answer and explanation

Correct answers: A, B, D

Explanation

To securely manage sensitive data in AWS Systems Manager Parameter Store, you must ensure that access control is enforced and unauthorized access attempts are logged. IAM policies control who can access the parameters, AWS CloudTrail provides a record of access attempts, and encrypting SecureString parameters with a KMS key ensures data security. Resource-based policies and versioning are either unsupported or irrelevant in this case.

  • A. Correct.

    Attaching an IAM policy to the specific roles granting access to the SecureString parameters ensures that only authorized roles can read or write to the parameters. This is a key step in enforcing access control.

  • B. Correct.

    Enabling AWS CloudTrail ensures that all API calls and access attempts to the Parameter Store are logged, which is critical for auditing and detecting unauthorized access attempts.

  • C. Incorrect.

    You cannot directly attach a resource-based policy to Parameter Store parameters. Access control for Parameter Store is managed through IAM policies and, optionally, KMS policies.

  • D. Correct.

    Using a KMS key to encrypt SecureString parameters adds an additional layer of security. Access to the parameters can be further restricted by controlling access to the associated KMS key.

  • E. Incorrect.

    Parameter Store does not support versioning for SecureString parameters. This option is not valid.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam