SCS-C02 exam dumps

SCS-C02 practice question 455 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 455

Select 3

You are responsible for managing the security of your AWS environment, and your team uses AWS CloudFormation templates to deploy infrastructure. To ensure deployment best practices, you want to prevent unauthorized updates to your resources, detect changes made outside of CloudFormation, and minimize risks from unapproved template modifications. Which actions should you take?

  1. A

    Enable drift detection on your CloudFormation stacks to identify unauthorized changes made outside of CloudFormation.

  2. B

    Use AWS Config to monitor CloudFormation stack compliance with organizational policies.

  3. C

    Implement IAM policies that allow all developers to directly modify resources created by CloudFormation for flexibility.

  4. D

    Leverage CloudFormation change sets to review changes before applying updates to your stacks.

  5. E

    Enable encryption for all sensitive data in your CloudFormation templates.

Show answer and explanation

Correct answers: A, B, D

Explanation

To follow deployment best practices with infrastructure as code, you should enable drift detection to monitor for unauthorized changes, use AWS Config to enforce compliance with organizational policies, and leverage CloudFormation change sets to review changes before they are applied. These actions ensure the security, integrity, and compliance of your CloudFormation-managed infrastructure.

  • A. Correct.

    Drift detection is a critical feature that helps identify resources that have been modified or created outside of AWS CloudFormation, ensuring the stack's integrity and alignment with the defined template.

  • B. Correct.

    AWS Config is a useful service for monitoring compliance, and it can ensure that CloudFormation stacks adhere to organizational security and compliance policies.

  • C. Incorrect.

    Allowing all developers to directly modify resources created by CloudFormation is against best practices, as it increases the risk of accidental or unauthorized changes.

  • D. Correct.

    CloudFormation change sets allow you to preview and validate changes before applying them, helping to prevent unauthorized or risky updates to your infrastructure.

  • E. Incorrect.

    While encryption for sensitive data is important, it is unrelated to the specific objectives of preventing unauthorized updates or detecting drift in CloudFormation stacks.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam