SCS-C02 exam dumps

SCS-C02 practice question 446 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 446

Select 2

An organization wants to implement a secure and consistent deployment strategy for their cloud resources. They are using AWS CloudFormation to automate resource provisioning. To ensure security and consistency, they want to enforce that CloudFormation templates are compliant with the company's security policies before deployment. Which combination of solutions would best address this requirement?

  1. A

    Use AWS Config with custom rules to validate CloudFormation stack compliance after deployment.

  2. B

    Enable AWS CloudFormation Guard to validate templates against predefined rules during deployment.

  3. C

    Implement a CI/CD pipeline with validation steps using AWS CodePipeline and AWS CloudFormation Guard.

  4. D

    Use AWS Trusted Advisor to validate the security of CloudFormation templates before deployment.

  5. E

    Store CloudFormation templates in an S3 bucket with versioning and apply an S3 bucket policy to restrict access.

Show answer and explanation

Correct answers: B, C

Explanation

To implement a secure and consistent deployment strategy for cloud resources, it's essential to validate CloudFormation templates against security policies before deployment. AWS CloudFormation Guard ensures the templates adhere to predefined rules, and integrating this with a CI/CD pipeline automates the validation process, ensuring compliance and consistency at scale. Post-deployment monitoring tools like AWS Config are complementary but not sufficient for pre-deployment validation.

  • A. Incorrect.

    AWS Config is used to monitor resource compliance after deployment, not to validate CloudFormation templates before deployment.

  • B. Correct.

    AWS CloudFormation Guard is specifically designed to validate CloudFormation templates against security and compliance rules during deployment, ensuring consistency.

  • C. Correct.

    Using a CI/CD pipeline with AWS CodePipeline and AWS CloudFormation Guard allows for automated validation and testing of templates, ensuring secure and consistent deployments.

  • D. Incorrect.

    AWS Trusted Advisor provides recommendations for cost, performance, and security but does not validate CloudFormation templates directly.

  • E. Incorrect.

    Storing templates in S3 with versioning and access control enhances security but does not enforce compliance or validate consistency of the templates.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam