SCS-C02 exam dumps

SCS-C02 practice question 484 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 484

Select 3

An organization performs a security review of its AWS architecture and notices that sensitive data stored in Amazon S3 is not encrypted, leading to potential compliance violations. Additionally, the organization observes that the S3 bucket is configured with public access, exposing data unnecessarily. As a solution, the security team wants to address these gaps immediately and determine which changes would also reduce costs. Which of the following actions should the security team take?

  1. A

    Enable server-side encryption (SSE) for the S3 bucket to encrypt data at rest.

  2. B

    Enable S3 Object Lock on the bucket to prevent accidental deletion of objects.

  3. C

    Use AWS Identity and Access Management (IAM) policies to restrict access to the S3 bucket.

  4. D

    Enable the 'Block Public Access' feature for the S3 bucket to prevent public access.

  5. E

    Enable Amazon S3 Transfer Acceleration to improve data transfer speeds.

Show answer and explanation

Correct answers: A, C, D

Explanation

The organization identified two primary security gaps: lack of encryption for data at rest and unintended public access to the S3 bucket. Enabling server-side encryption (SSE), using IAM policies to restrict access, and enabling the 'Block Public Access' feature directly address these gaps without incurring additional costs. These actions improve the security posture while aligning with the organization's objective of cost-effectiveness. S3 Object Lock and Transfer Acceleration, while useful in other contexts, do not address the identified issues or reduce costs.

  • A. Correct.

    Enabling server-side encryption ensures data is encrypted at rest, improving security. It also does not incur additional costs, making it a cost-effective solution.

  • B. Incorrect.

    Enabling S3 Object Lock is important for preventing accidental deletion, but it does not directly address the identified security gaps of encryption and public access, nor does it reduce costs.

  • C. Correct.

    Using IAM policies to restrict access to the S3 bucket improves access control and security, ensuring only authorized users can access the data. This action does not add additional costs.

  • D. Correct.

    Enabling the 'Block Public Access' feature prevents the bucket from being publicly accessible, mitigating the risk of data exposure. It is also a cost-neutral action.

  • E. Incorrect.

    Enabling S3 Transfer Acceleration improves data transfer speeds but is unrelated to addressing security gaps or reducing costs. Additionally, this feature incurs additional charges.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam