SOA-C02 exam dumps

SOA-C02 practice question 203 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 203

Select 2

A company has implemented a data classification scheme to categorize its data into 'Confidential', 'Restricted', and 'Public'. They want to enforce this classification scheme across their AWS account to ensure that objects in Amazon S3 buckets are appropriately tagged and comply with the classification policy. Which combination of solutions should the SysOps administrator implement to meet this requirement?

  1. A

    Use AWS Config with a custom rule to check if S3 objects have the correct classification tags.

  2. B

    Enable S3 Object Lock to automatically enforce data classification on all objects.

  3. C

    Create an S3 bucket policy that requires all uploaded objects to include specific classification tags.

  4. D

    Use Amazon Macie to automatically classify and tag sensitive data stored in S3 buckets.

  5. E

    Set up an S3 Lifecycle policy to enforce tagging based on data classification rules.

Show answer and explanation

Correct answers: A, C

Explanation

To enforce a data classification scheme, AWS Config with a custom rule is suitable for checking compliance with tagging requirements, while an S3 bucket policy can enforce tagging by preventing non-compliant uploads. These solutions work together to ensure that the classification scheme is adhered to. Other options, like S3 Object Lock and Amazon Macie, do not directly enforce tagging or classification rules, and S3 Lifecycle policies are unrelated to tagging enforcement.

  • A. Correct.

    AWS Config with a custom rule can evaluate whether S3 objects have the required tags, helping to enforce the data classification scheme.

  • B. Incorrect.

    S3 Object Lock is designed to enforce WORM (Write Once, Read Many) protection and does not enforce tagging or classification policies.

  • C. Correct.

    An S3 bucket policy can be used to enforce tagging by denying uploads of objects that do not include required tags, ensuring compliance with the classification scheme.

  • D. Incorrect.

    Amazon Macie is a tool for discovering and identifying sensitive data, but it does not enforce tagging or apply pre-defined classification schemes directly.

  • E. Incorrect.

    S3 Lifecycle policies are used for managing the lifecycle of objects, such as transitioning them to different storage classes or deleting them, but they do not enforce tagging or classification rules.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam