SCS-C02 exam dumps

SCS-C02 practice question 449 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 449

Select 3

Your company utilizes an Amazon S3 bucket to store sensitive customer data. To ensure compliance with regulatory requirements, the data in the bucket must be encrypted, and access should be restricted to specific IAM roles. Recently, an internal audit discovered that some objects in the bucket were uploaded without encryption. What steps can you take to enforce encryption and restrict access to the bucket?

  1. A

    Create an S3 bucket policy that denies any PUT requests without the 'x-amz-server-side-encryption' header.

  2. B

    Enable default encryption on the S3 bucket to ensure all future objects are encrypted automatically.

  3. C

    Use AWS Config to enable the rule 's3-bucket-server-side-encryption-enabled' to monitor and enforce encryption compliance.

  4. D

    Enable versioning on the S3 bucket to track changes and ensure compliance with encryption requirements.

  5. E

    Attach an IAM policy to the roles that explicitly denies access to the bucket unless encryption is used.

Show answer and explanation

Correct answers: A, B, C

Explanation

To ensure compliance with encryption requirements, you can use a combination of S3 bucket policies, default encryption, and monitoring tools like AWS Config. A bucket policy can reject uploads that lack encryption headers, while enabling default encryption ensures that all new objects are encrypted automatically. AWS Config can monitor and enforce compliance. Versioning and IAM policies, while useful in other contexts, do not directly address the enforcement of encryption requirements.

  • A. Correct.

    This option is correct. A bucket policy can be used to enforce encryption by rejecting any upload requests that do not include the 'x-amz-server-side-encryption' header, ensuring that objects are encrypted.

  • B. Correct.

    This option is correct. Enabling default encryption on the bucket ensures that all new objects are automatically encrypted with a specified encryption method, meeting compliance requirements.

  • C. Correct.

    This option is correct. AWS Config can monitor the compliance of the bucket's encryption settings and alert or remediate if objects are not encrypted.

  • D. Incorrect.

    This option is incorrect. While versioning is a good practice for data protection, it does not enforce encryption or restrict access to the bucket.

  • E. Incorrect.

    This option is incorrect. IAM policies are used to manage access, but they cannot enforce encryption directly. The enforcement of encryption should be handled through bucket policies and default encryption settings.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam