SCS-C02 exam dumps

SCS-C02 practice question 472 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 472

Select 3

An organization needs to secure sensitive customer data stored in an Amazon S3 bucket. The security team wants to ensure that the data is encrypted at rest, only accessible to specific IAM roles, and that any unauthorized access attempts are logged. Which combination of steps will help the organization achieve this goal?

  1. A

    Enable server-side encryption with AWS Key Management Service (SSE-KMS) for the S3 bucket.

  2. B

    Set a bucket policy to allow access only from specific IAM roles.

  3. C

    Enable S3 Transfer Acceleration to encrypt data in transit.

  4. D

    Turn on Amazon S3 server access logging to capture access attempts.

  5. E

    Use Amazon GuardDuty to monitor and block unauthorized access to the S3 bucket.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure sensitive customer data in an S3 bucket, the organization needs to implement encryption at rest, restrict access to specific IAM roles, and monitor unauthorized access attempts. Enabling SSE-KMS ensures encryption, while a bucket policy controls access. Turning on server access logging allows the organization to analyze and respond to access attempts. S3 Transfer Acceleration and GuardDuty are not directly relevant to the scenario's requirements.

  • A. Correct.

    Correct. Enabling SSE-KMS ensures that the data is encrypted at rest using a managed key from AWS KMS.

  • B. Correct.

    Correct. A bucket policy allows fine-grained access control to the S3 bucket, ensuring only specific IAM roles can access the data.

  • C. Incorrect.

    Incorrect. S3 Transfer Acceleration is used to improve upload speed for objects in S3, not for encryption or access control.

  • D. Correct.

    Correct. Enabling server access logging ensures that all access attempts, including unauthorized ones, are logged for security analysis.

  • E. Incorrect.

    Incorrect. While Amazon GuardDuty is useful for monitoring suspicious activity across your AWS account, it does not directly block or log unauthorized access to an S3 bucket.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam