SCS-C02 exam dumps

SCS-C02 practice question 423 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 423

Select 4

Your organization has implemented Amazon S3 to store sensitive financial reports. As part of compliance requirements, you need to ensure that all data is encrypted both at rest and in transit. Additionally, you must have visibility into access patterns and detect any unauthorized access attempts. What combination of solutions would meet these requirements?

  1. A

    Enable default encryption on the S3 bucket using an AWS Key Management Service (KMS) key.

  2. B

    Enable Amazon S3 server access logging and analyze the logs using Amazon CloudWatch Logs.

  3. C

    Use Amazon Macie to monitor and detect unusual access patterns to the sensitive data.

  4. D

    Enable public access to the S3 bucket to allow external auditors to view the reports.

  5. E

    Configure an S3 bucket policy to deny unencrypted PUT requests.

Show answer and explanation

Correct answers: A, B, C, E

Explanation

To meet the compliance requirements for encryption at rest and in transit, and to monitor access patterns, you need to enable default encryption on the S3 bucket, deny unencrypted PUT requests, and use Amazon Macie for anomaly detection. Additionally, enabling server access logging provides valuable insights into access patterns and helps detect unauthorized access attempts. Allowing public access to the bucket would compromise security and is not a valid solution.

  • A. Correct.

    Enabling default encryption on the S3 bucket using an AWS KMS key ensures that all objects stored in the bucket are encrypted at rest, meeting compliance requirements.

  • B. Correct.

    Enabling Amazon S3 server access logging allows you to capture detailed information about access requests made to the bucket, which can be analyzed using CloudWatch Logs for visibility into access patterns.

  • C. Correct.

    Amazon Macie uses machine learning to monitor and detect unusual data access patterns, providing insights into potential unauthorized access attempts.

  • D. Incorrect.

    Enabling public access to the S3 bucket would expose sensitive financial reports to the internet, violating security best practices and compliance requirements.

  • E. Correct.

    Configuring an S3 bucket policy to deny unencrypted PUT requests ensures that data being uploaded to the bucket is encrypted in transit, fulfilling the requirement for encryption during data transfer.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam