SCS-C02 exam dumps

SCS-C02 practice question 480 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 480

Select 2

Your organization has a security compliance requirement to ensure that all Amazon S3 buckets are configured to prohibit public access. As a security engineer, you need to implement an automated solution to continuously evaluate the configurations of S3 buckets and notify the team if any bucket violates this policy. Which combination of actions should you take to achieve this using AWS services?

  1. A

    Enable AWS Config and create a custom Config rule to check for S3 bucket public access settings.

  2. B

    Use AWS Config's managed rule 's3-bucket-public-read-prohibited' to monitor S3 bucket public read access.

  3. C

    Set up an Amazon SNS topic and subscribe the security team to receive notifications from AWS Config.

  4. D

    Enable CloudTrail and configure a trail to log all S3 bucket configurations for manual auditing.

  5. E

    Manually inspect S3 bucket permissions in the AWS Management Console on a weekly basis.

Show answer and explanation

Correct answers: B, C

Explanation

The best solution involves leveraging AWS Config's managed rules to automatically evaluate S3 bucket configurations against compliance requirements and integrating Amazon SNS for real-time notifications. This approach ensures continuous monitoring and immediate alerting for policy violations, fulfilling the compliance requirements in an automated and scalable manner.

  • A. Incorrect.

    While a custom Config rule could work, AWS Config already provides a managed rule ('s3-bucket-public-read-prohibited') specifically designed for this purpose. Using the managed rule is more efficient and easier to maintain.

  • B. Correct.

    This is correct because AWS Config's managed rule 's3-bucket-public-read-prohibited' is specifically designed to evaluate whether S3 buckets allow public read access. It simplifies compliance checks.

  • C. Correct.

    This is correct because an Amazon SNS topic can be used to notify the security team whenever AWS Config detects a non-compliant resource. This ensures timely monitoring and response.

  • D. Incorrect.

    While enabling CloudTrail can provide logs for auditing, it does not actively evaluate the compliance of S3 bucket configurations. AWS Config is the better tool for continuous automated evaluation.

  • E. Incorrect.

    Manually inspecting S3 bucket permissions is not a scalable or reliable method for continuous compliance monitoring. Utilizing AWS Config and automated notifications is more effective.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam