SCS-C02 exam dumps

SCS-C02 practice question 70 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 70

Select 2

Your organization is using Amazon S3 to store sensitive data, and an IAM user has reported that an S3 bucket policy was recently modified, allowing public access to the bucket. To perform a root cause analysis, which steps would help you identify the source of the change?

  1. A

    Analyze AWS CloudTrail logs for events related to the S3 bucket policy changes.

  2. B

    Check the IAM Access Analyzer to identify entities with access to the bucket.

  3. C

    Use AWS Config to review the configuration history of the S3 bucket.

  4. D

    Inspect the Amazon S3 Server Access Logs for recent requests.

  5. E

    Enable GuardDuty to detect unauthorized changes to the bucket policy.

Show answer and explanation

Correct answers: A, C

Explanation

To perform root cause analysis on an S3 bucket policy change, it is crucial to use tools that provide historical and event-level data. AWS CloudTrail logs detail actions performed on resources, including S3 bucket policy modifications. Additionally, AWS Config provides a configuration history, which is invaluable for identifying changes over time and the source of those changes. While IAM Access Analyzer, S3 Server Access Logs, and GuardDuty are useful for other security purposes, they do not directly assist in determining the root cause of policy changes.

  • A. Correct.

    AWS CloudTrail logs provide detailed event history of actions taken on AWS resources, including S3 bucket policy changes. This is a critical step in identifying the source of the change.

  • B. Incorrect.

    IAM Access Analyzer helps identify external entities with access to resources but does not provide information about who or what made changes to the bucket policy.

  • C. Correct.

    AWS Config enables you to view the configuration history of your resources, including S3 bucket policies. This can help pinpoint when and how the policy was changed.

  • D. Incorrect.

    Amazon S3 Server Access Logs capture details about requests made to the bucket, but they do not provide information about bucket policy changes.

  • E. Incorrect.

    GuardDuty is a threat detection service and does not log or analyze policy changes to resources like S3 buckets.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam