SCS-C02 exam dumps

SCS-C02 practice question 454 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 454

Select 2

Your organization is using AWS CloudFormation to manage infrastructure as code (IaC). As part of improving security and operational resilience, you need to ensure that your CloudFormation stacks are hardened and remain consistent with the templates deployed. Which of the following approaches should you include in your deployment process? (Select TWO)

  1. A

    Enable drift detection on CloudFormation stacks and periodically review detected drifts.

  2. B

    Use IAM roles with administrator-level permissions to execute CloudFormation stacks.

  3. C

    Implement resource policies and explicit deny rules in the CloudFormation templates where applicable.

  4. D

    Use hardcoded secrets in CloudFormation templates to simplify authentication deployments.

  5. E

    Enable stack termination protection for critical CloudFormation stacks.

Show answer and explanation

Correct answers: A, C

Explanation

To ensure secure and resilient CloudFormation deployments, it is crucial to use mechanisms like drift detection to maintain consistency between deployed resources and templates. Additionally, hardening templates by incorporating resource policies and deny rules strengthens security. Other options, such as using administrator roles or hardcoding secrets, introduce unnecessary risks or do not directly address the given security goals.

  • A. Correct.

    Correct: Enabling drift detection allows you to identify and address discrepancies between your CloudFormation stack's actual resources and the defined template, ensuring consistency and compliance.

  • B. Incorrect.

    Incorrect: Using IAM roles with administrator-level permissions is overly permissive and goes against the principle of least privilege, increasing the risk of accidental or malicious changes.

  • C. Correct.

    Correct: Including resource policies and explicit deny rules in templates helps restrict access to resources, enhancing security at the infrastructure level.

  • D. Incorrect.

    Incorrect: Hardcoding secrets in templates is a security risk, as it exposes sensitive data. Secrets should be managed using AWS Secrets Manager, Parameter Store, or other secure mechanisms.

  • E. Incorrect.

    Incorrect: While enabling stack termination protection is beneficial for preventing accidental deletions, it does not directly address hardening or drift detection in CloudFormation stacks.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam