SCS-C02 exam dumps

SCS-C02 practice question 92 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 92

Select 3

You are a Security Engineer tasked with securing an Amazon S3 bucket that stores sensitive customer data. The bucket must allow access only to specific users within your AWS Organization and restrict all public access. Additionally, you must ensure that objects cannot be accidentally deleted by any user. Which combination of steps would meet these requirements?

  1. A

    Enable the 'Block Public Access' setting at the bucket level.

  2. B

    Attach a bucket policy that allows access only to specific AWS Organization principals.

  3. C

    Enable MFA Delete on the S3 bucket.

  4. D

    Use an IAM role with full S3 permissions and assign it to all users in the organization.

  5. E

    Enable Amazon Macie to automatically classify sensitive data in the bucket.

Show answer and explanation

Correct answers: A, B, C

Explanation

To secure the S3 bucket and meet the specified requirements, you must take steps to block public access, restrict access to specific users within the AWS Organization, and prevent accidental deletions. 'Block Public Access' ensures no public access to the bucket, the bucket policy limits access to authorized AWS Organization principals, and enabling MFA Delete protects against accidental deletions. Using an IAM role with full permissions or enabling Amazon Macie does not address the core security requirements in this scenario.

  • A. Correct.

    Enabling 'Block Public Access' ensures that the bucket cannot be publicly accessible, which is critical for securing sensitive data.

  • B. Correct.

    A bucket policy restricting access to specific AWS Organization principals ensures that only authorized users within your organization can access the bucket.

  • C. Correct.

    Enabling MFA Delete adds an additional layer of protection by requiring multi-factor authentication before deleting objects, preventing accidental deletions.

  • D. Incorrect.

    Assigning an IAM role with full S3 permissions to all users in the organization does not restrict access to sensitive data and violates the principle of least privilege.

  • E. Incorrect.

    Amazon Macie is a useful tool for identifying sensitive data but does not directly address the requirements for access control or accidental deletion prevention in this scenario.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam