SCS-C02 exam dumps

SCS-C02 practice question 487 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 487

Select 3

An organization is conducting an architectural review of its AWS environment to identify security gaps and cost inefficiencies. During the review, it is discovered that several Amazon S3 buckets storing sensitive data are publicly accessible, and an EC2 instance running a legacy application has been left running continuously in a non-production environment, resulting in unnecessary costs. What should the organization do to address these issues?

  1. A

    Enable S3 Block Public Access at the account level to prevent public access to all S3 buckets.

  2. B

    Implement an IAM policy to deny public access to all Amazon S3 buckets.

  3. C

    Use AWS Trusted Advisor to identify and terminate the EC2 instance in the non-production environment.

  4. D

    Enable AWS Config rules to monitor S3 bucket policies for public access and remediate non-compliant buckets.

  5. E

    Set up a budget using AWS Budgets to alert stakeholders when cost thresholds are exceeded.

Show answer and explanation

Correct answers: A, D, E

Explanation

The organization must address both security and cost inefficiencies. Enabling S3 Block Public Access at the account level ensures that no bucket can be made publicly accessible, effectively mitigating the security risk. AWS Config rules can provide continuous compliance monitoring and automatic remediation, ensuring long-term security. To address cost inefficiencies, AWS Budgets can be used to monitor spending and alert stakeholders when costs exceed predefined limits. These combined actions provide a comprehensive approach to resolving both identified issues.

  • A. Correct.

    Correct. Enabling S3 Block Public Access at the account level ensures that no S3 bucket in the account can be made publicly accessible, addressing the security gap comprehensively.

  • B. Incorrect.

    Incorrect. While an IAM policy can restrict access to S3 buckets, it is not the most effective solution for managing public access at scale, as S3 Block Public Access provides a simpler and more reliable method.

  • C. Incorrect.

    Incorrect. AWS Trusted Advisor can identify idle or underutilized EC2 instances, but it does not have the capability to terminate them. Additional manual actions or automation would be required.

  • D. Correct.

    Correct. AWS Config rules can continuously monitor the compliance of S3 bucket policies and automatically remediate any public access configurations, effectively addressing the security gap.

  • E. Correct.

    Correct. Setting up AWS Budgets can help monitor and control costs by notifying stakeholders when spending exceeds predefined thresholds, addressing the unnecessary cost associated with the EC2 instance.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam