SCS-C02 exam dumps

SCS-C02 practice question 75 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 75

Select 3

Your company is using Amazon Kinesis Data Streams to process real-time clickstream data from a web application. The security team has mandated that all data being ingested into Kinesis must be encrypted at rest and in transit, while ensuring auditability of the data flow. Which combination of actions should you take to meet these requirements?

  1. A

    Enable server-side encryption (SSE) for the Kinesis Data Stream using an AWS KMS key.

  2. B

    Use HTTPS endpoints to secure data in transit to the Kinesis Data Stream.

  3. C

    Enable CloudTrail logging for Kinesis to track API activity.

  4. D

    Use client-side encryption before sending data to Kinesis.

  5. E

    Enable S3 bucket versioning where Kinesis data is being stored.

Show answer and explanation

Correct answers: A, B, C

Explanation

To meet the security team's requirements, you need to ensure that data is encrypted both at rest and in transit, and that API activities are auditable. Enabling server-side encryption in Kinesis ensures encryption at rest using an AWS KMS key. Using HTTPS ensures secure data transmission to Kinesis. Enabling CloudTrail logging for Kinesis allows tracking of API activity for audit purposes. These actions fulfill all the specified requirements. While client-side encryption and S3 versioning are useful in other contexts, they are either redundant or irrelevant to this specific scenario.

  • A. Correct.

    Enabling server-side encryption ensures that data at rest in the Kinesis Data Stream is encrypted using an AWS KMS key, meeting the encryption requirement.

  • B. Correct.

    Using HTTPS ensures that data in transit is encrypted, fulfilling the requirement to secure data while being transmitted to the Kinesis Data Stream.

  • C. Correct.

    Enabling CloudTrail logging for Kinesis provides an audit trail of API activity, ensuring auditability of the data flow as mandated by the security team.

  • D. Incorrect.

    While client-side encryption is a valid approach to securing data, it is not strictly necessary when server-side encryption is already enabled in this scenario.

  • E. Incorrect.

    Enabling S3 bucket versioning is unrelated to the requirements for encrypting and auditing data in Kinesis.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam