SOA-C02 exam dumps

SOA-C02 practice question 165 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 165

Select 2

A company is using an Amazon S3 bucket to store sensitive customer documents. The SysOps Administrator is tasked with ensuring the data is protected and only accessible to authorized users. The administrator must also ensure compliance with the company's security policies, which require encryption at rest and logging of access requests to the bucket. Which combination of steps should the administrator take to meet these requirements?

  1. A

    Enable server-side encryption (SSE) on the S3 bucket.

  2. B

    Attach an Amazon S3 bucket policy that denies access to all users.

  3. C

    Enable S3 bucket logging or AWS CloudTrail for the bucket.

  4. D

    Use Amazon Macie to automatically identify sensitive data in the bucket.

  5. E

    Enable versioning on the S3 bucket.

Show answer and explanation

Correct answers: A, C

Explanation

To meet the company's security and compliance requirements, the administrator must ensure the data is encrypted at rest and access requests are logged. Enabling server-side encryption (SSE) fulfills the encryption requirement, while enabling S3 bucket logging or AWS CloudTrail fulfills the logging requirement. The other options either do not address the specified requirements or are unrelated to the scenario.

  • A. Correct.

    Enabling server-side encryption ensures that data is encrypted at rest, which is a requirement for securing sensitive data.

  • B. Incorrect.

    Denying access to all users would make the bucket entirely inaccessible, which is not a practical solution for authorized access.

  • C. Correct.

    Enabling S3 bucket logging or AWS CloudTrail ensures that access requests to the bucket are logged, helping meet compliance requirements.

  • D. Incorrect.

    While Amazon Macie can help identify sensitive data, it does not directly fulfill the requirements for encryption or logging.

  • E. Incorrect.

    Enabling versioning is useful for backup and recovery but is not directly relevant to encryption or logging requirements.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam