SOA-C02 exam dumps

SOA-C02 practice question 200 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 200

Select 2

Your organization has a critical web application hosted on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive customer data in an Amazon RDS database. To comply with company security policies, you need to implement measures to protect this sensitive data and secure the infrastructure. Which of the following actions should you take? (Select TWO)

  1. A

    Enable encryption at rest for the Amazon RDS database using AWS KMS.

  2. B

    Associate an AWS WAF web ACL with the Application Load Balancer.

  3. C

    Launch the EC2 instances in a publicly accessible subnet for better performance.

  4. D

    Enable S3 bucket versioning for application backups.

  5. E

    Configure security groups to allow access to the EC2 instances only from the ALB.

Show answer and explanation

Correct answers: A, B

Explanation

To implement data and infrastructure protection strategies, you must address both the security of sensitive data and the protection of the application infrastructure. Encrypting the RDS database ensures that sensitive data is protected at rest, meeting compliance and security requirements. Adding AWS WAF to the ALB secures the infrastructure by mitigating common web vulnerabilities. These actions align directly with the task of protecting both data and infrastructure.

  • A. Correct.

    Enabling encryption at rest for the Amazon RDS database using AWS KMS protects sensitive customer data stored in the database, which is a critical part of implementing data protection strategies.

  • B. Correct.

    Associating an AWS WAF web ACL with the Application Load Balancer helps protect the application from common web exploits, securing the infrastructure against threats.

  • C. Incorrect.

    Launching EC2 instances in a publicly accessible subnet increases the attack surface and violates security best practices. EC2 instances should reside in private subnets for better security.

  • D. Incorrect.

    While enabling S3 bucket versioning is a good practice for data durability and recovery, it is not directly related to protecting the sensitive data or securing the infrastructure in this scenario.

  • E. Incorrect.

    Configuring security groups to allow access to the EC2 instances only from the ALB is a good security measure but is not as critical as the correct answers in terms of protecting data and infrastructure comprehensively.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam