SOA-C02 exam dumps

SOA-C02 practice question 197 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 197

Select 3

Your organization is hosting a critical application on Amazon EC2 instances in a production environment. The application processes sensitive customer data, and compliance requirements mandate encryption of this data in transit and at rest. Additionally, the organization wants to ensure that only specific IAM roles and users can access the underlying infrastructure. Which combination of solutions should you implement to meet these requirements?

  1. A

    Enable Amazon S3 default encryption for any S3 buckets storing sensitive data.

  2. B

    Use AWS Key Management Service (KMS) to manage encryption keys and ensure data encryption for EBS volumes attached to the EC2 instances.

  3. C

    Configure a VPC endpoint to ensure EC2 instances communicate securely with S3 without traversing the public internet.

  4. D

    Apply an IAM policy that restricts access to EC2 resources to only specific IAM roles and users.

  5. E

    Enable EC2 instance-level encryption by modifying the instance metadata.

Show answer and explanation

Correct answers: A, B, D

Explanation

To meet the requirements of encrypting data in transit and at rest while implementing access control, you should first enable default encryption for S3 to handle data at rest in S3 and use AWS KMS to encrypt EBS volumes for data at rest in EC2. Additionally, applying IAM policies ensures that only specific users and roles have access to the EC2 infrastructure. Configuring a VPC endpoint, while beneficial for enhanced security, is not directly tied to the problem statement's encryption and access control requirements. Lastly, EC2 instance-level encryption isn't a valid option because encryption is handled at the storage or protocol level.

  • A. Correct.

    This option is correct because enabling Amazon S3 default encryption ensures that any sensitive data stored in S3 is automatically encrypted at rest, fulfilling the compliance requirement for data protection.

  • B. Correct.

    This option is correct because AWS Key Management Service (KMS) can be used to manage encryption keys and encrypt Amazon EBS volumes. This ensures that the sensitive customer data processed by EC2 instances is encrypted at rest.

  • C. Incorrect.

    While configuring a VPC endpoint does improve security by avoiding public internet exposure, it is not explicitly required for meeting the encryption and access control requirements specified in this scenario.

  • D. Correct.

    This option is correct because applying an IAM policy to restrict access to EC2 resources ensures that only authorized IAM roles and users can access the underlying infrastructure, fulfilling the access control requirement.

  • E. Incorrect.

    This option is incorrect because EC2 does not support instance-level encryption. Instead, encryption should be applied at the storage (EBS) level or for data in transit using protocols like TLS.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam