SCS-C02 exam dumps

SCS-C02 practice question 482 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 482

Single answer

Your company is using multiple AWS services and resources in production. As part of a compliance requirement, you need to ensure that all Amazon S3 buckets are encrypted at rest and that specific IAM roles do not have permissions to delete critical CloudTrail logs. Which approach should you take to assess and monitor these configurations effectively on an ongoing basis?

  1. A

    Use AWS Config to create custom config rules to check for S3 bucket encryption and IAM role permissions.

  2. B

    Manually review the S3 bucket encryption settings and IAM role permissions in the AWS Management Console.

  3. C

    Enable AWS CloudTrail to track API calls and verify the settings for S3 bucket encryption and IAM role permissions.

  4. D

    Use AWS Trusted Advisor to monitor S3 bucket encryption and IAM role permissions compliance.

Show answer and explanation

Correct answer: A

Explanation

AWS Config is designed to assess, audit, and evaluate the configurations of AWS resources. By using AWS Config, you can create custom rules to enforce compliance with specific security requirements, such as verifying S3 bucket encryption and restricting IAM role permissions. Other options, like manual reviews or using CloudTrail, do not provide the same level of automation and continuous monitoring as AWS Config.

  • A. Correct.

    This is the correct answer. AWS Config allows you to create custom config rules to continuously evaluate whether resources, such as S3 buckets and IAM roles, comply with your defined security policies. This is the most effective and automated approach for assessment and monitoring.

  • B. Incorrect.

    This is incorrect. Manually reviewing configurations in the AWS Management Console is time-consuming, prone to human error, and not scalable for ongoing compliance monitoring.

  • C. Incorrect.

    This is incorrect. While AWS CloudTrail can log API calls related to S3 and IAM, it does not actively evaluate configurations or enforce compliance with defined rules.

  • D. Incorrect.

    This is incorrect. AWS Trusted Advisor provides high-level recommendations, but it does not provide the detailed, customizable compliance checks that AWS Config offers for evaluating specific resource configurations.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam