SCS-C02 exam dumps

SCS-C02 practice question 68 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 68

Select 3

An organization is designing a multi-tenant application where each tenant's data must be strictly isolated from others. They are using Amazon S3 to store tenant-specific data and want to implement resource isolation mechanisms to meet this requirement. Which combination of mechanisms should they use to ensure data isolation?

  1. A

    Create separate S3 buckets for each tenant and use bucket policies to restrict access.

  2. B

    Use a single S3 bucket with object prefixes for each tenant and configure IAM policies to isolate access.

  3. C

    Enable S3 Block Public Access settings to ensure no bucket or object is publicly accessible.

  4. D

    Encrypt all objects stored in S3 using a tenant-specific AWS KMS key.

  5. E

    Use Amazon Macie to monitor and classify tenant data stored in S3.

Show answer and explanation

Correct answers: A, B, D

Explanation

To ensure resource isolation in a multi-tenant environment, the organization can either use separate S3 buckets for each tenant or a single bucket with tenant-specific prefixes along with IAM policies to control access. Additionally, encrypting data with tenant-specific AWS KMS keys enhances isolation by ensuring that each tenant's data is protected by a unique encryption key. While S3 Block Public Access and Amazon Macie are useful security tools, they do not directly address the requirement for isolating tenant data.

  • A. Correct.

    Creating separate S3 buckets for each tenant and using bucket policies to restrict access is an effective way to achieve data isolation. Each bucket can have its own access control policies, ensuring strict separation between tenants.

  • B. Correct.

    Using a single S3 bucket with object prefixes for each tenant and configuring IAM policies to isolate access is another valid approach. IAM policies can precisely control access to specific prefixes within the bucket, ensuring data isolation.

  • C. Incorrect.

    While enabling S3 Block Public Access settings is a good security practice, it does not specifically address tenant data isolation requirements. It only prevents unintended public access to the data.

  • D. Correct.

    Encrypting objects with tenant-specific AWS KMS keys provides an additional layer of isolation by ensuring that each tenant's data is encrypted with a unique key. This ensures that decryption is tightly controlled on a per-tenant basis.

  • E. Incorrect.

    Amazon Macie is a service for data classification and monitoring but does not directly contribute to resource isolation mechanisms for tenant-specific data.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam