SCS-C02 exam dumps

SCS-C02 practice question 459 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 459

Select 4

Your company has recently adopted a tagging strategy to better manage and secure resources in AWS. As the Security Engineer, you want to ensure that tagging practices are aligned with best practices to enhance security and compliance. Which of the following are best practices for tagging in AWS?

  1. A

    Use a consistent naming convention for tags across all AWS resources.

  2. B

    Restrict tagging to only the Security team to avoid unauthorized changes.

  3. C

    Use tags to categorize resources by environment, owner, and application.

  4. D

    Implement AWS Identity and Access Management (IAM) policies to control who can add, modify, or delete tags.

  5. E

    Avoid using tags for sensitive data to prevent accidental exposure.

Show answer and explanation

Correct answers: A, C, D, E

Explanation

Tagging is a critical practice for resource management, cost allocation, and security in AWS. Best practices include using consistent naming conventions, categorizing resources logically, controlling access to tagging via IAM policies, and avoiding the storage of sensitive data in tags. These practices enhance security, compliance, and operational efficiency.

  • A. Correct.

    Using consistent naming conventions for tags ensures that resources are easily identifiable and traceable, which is critical for management, security, and compliance.

  • B. Incorrect.

    Restricting tagging to only the Security team is not a best practice as multiple teams may need to tag resources for management, cost allocation, or operational purposes. Instead, access should be governed by IAM policies.

  • C. Correct.

    Using tags to categorize resources by environment, owner, and application helps with organization, cost allocation, and security oversight, aligning with best practices.

  • D. Correct.

    IAM policies should be implemented to control who can manage tags, ensuring that only authorized users can add, modify, or delete tags, which is a security best practice.

  • E. Correct.

    Avoiding the use of tags for sensitive data is a best practice because tags are not encrypted and could be exposed to users with read access to resource metadata.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam