SOA-C02 exam dumps

SOA-C02 practice question 202 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 202

Select 3

Your company has implemented a data classification scheme with three levels: Confidential, Internal, and Public. You need to enforce this classification scheme for data stored in Amazon S3. Which actions should you take to ensure compliance with the scheme?

  1. A

    Use S3 bucket policies to deny access to data labeled 'Confidential' unless accessed from approved IAM roles.

  2. B

    Tag S3 objects with a 'DataClassification' key and values like 'Confidential', 'Internal', or 'Public'.

  3. C

    Enable S3 Object Lock to prevent deletion of objects classified as 'Internal' or 'Confidential'.

  4. D

    Configure AWS Config rules to ensure that all S3 buckets have default encryption enabled.

  5. E

    Set up Amazon Macie to automatically detect and classify sensitive data within S3 buckets.

Show answer and explanation

Correct answers: A, B, D

Explanation

To enforce a data classification scheme in Amazon S3, you need mechanisms to control access based on classification (e.g., bucket policies), track classification metadata (e.g., object tagging), and ensure compliance with security policies (e.g., encryption via AWS Config rules). While Amazon Macie and S3 Object Lock are helpful for security and data protection, they do not directly enforce your classification scheme.

  • A. Correct.

    Using S3 bucket policies to deny access to specific data classifications ensures that access control is enforced based on your data classification scheme.

  • B. Correct.

    Tagging objects with a 'DataClassification' key helps maintain metadata about the classification level of each object, enabling streamlined management and compliance.

  • C. Incorrect.

    While S3 Object Lock prevents deletion or overwriting of objects, it is not directly related to enforcing a data classification scheme.

  • D. Correct.

    AWS Config rules can be used to ensure that encryption is enabled for all S3 buckets, which aligns with protecting sensitive data classifications like 'Confidential'.

  • E. Incorrect.

    Amazon Macie detects and classifies sensitive data, but it is a detection tool rather than an enforcement mechanism for a predefined data classification scheme.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam