SCS-C02 exam dumps

SCS-C02 practice question 451 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 451

Select 3

Your company has deployed an application that stores sensitive customer data in an Amazon S3 bucket. To comply with regulatory requirements, the data must be encrypted both in transit and at rest. The application uses the AWS SDK for accessing S3. Which combination of actions should you take to meet these requirements?

  1. A

    Enable Server-Side Encryption with AWS Key Management Service (SSE-KMS) on the S3 bucket.

  2. B

    Use HTTPS for all requests to the S3 bucket.

  3. C

    Enable S3 Versioning to maintain a record of all changes to objects in the bucket.

  4. D

    Use a bucket policy to enforce encryption by rejecting requests that do not include the 'x-amz-server-side-encryption' header.

  5. E

    Enable S3 Transfer Acceleration to improve data transfer speed and security.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the requirement of encrypting sensitive data both at rest and in transit, you must enable Server-Side Encryption with AWS Key Management Service (SSE-KMS) and use HTTPS for all communications with the S3 bucket. Additionally, enforcing encryption through a bucket policy ensures compliance by rejecting non-encrypted upload requests. S3 Versioning and Transfer Acceleration are useful features but do not address the core encryption requirements in this scenario.

  • A. Correct.

    Correct: Enabling Server-Side Encryption with AWS Key Management Service (SSE-KMS) ensures that data is encrypted at rest using AWS-managed or customer-managed keys.

  • B. Correct.

    Correct: Using HTTPS ensures that data is encrypted in transit, meeting the requirement for in-transit encryption.

  • C. Incorrect.

    Incorrect: While S3 Versioning is useful for maintaining object history, it does not directly contribute to meeting encryption requirements.

  • D. Correct.

    Correct: A bucket policy enforcing encryption ensures that all objects uploaded to the bucket are encrypted, helping to maintain compliance with regulatory requirements.

  • E. Incorrect.

    Incorrect: S3 Transfer Acceleration improves data transfer speeds but does not inherently provide encryption capabilities or address the specific requirements of encryption at rest and in transit.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam