SOA-C02 exam dumps

SOA-C02 practice question 222 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 222

Single answer

Your company uses AWS Security Hub to monitor security standards compliance across multiple AWS accounts. A recent Security Hub finding flagged an Amazon S3 bucket as publicly accessible and non-compliant with your organization's security policy. What is the most appropriate action to resolve this issue while ensuring compliance and maintaining minimal risk?

  1. A

    Use the AWS CLI to immediately delete the S3 bucket to prevent further exposure.

  2. B

    Update the bucket policy to explicitly deny all public access and enable 'Block Public Access' settings.

  3. C

    Ignore the finding since public access might be necessary for the application.

  4. D

    Enable AWS Config rules to automatically delete any S3 bucket with public access.

Show answer and explanation

Correct answer: B

Explanation

AWS Security Hub findings help identify security issues and non-compliance in your AWS environment. In this scenario, resolving the public access issue for the flagged S3 bucket involves updating the bucket policy and enabling 'Block Public Access' settings. This approach effectively addresses the finding while minimizing risk and ensuring compliance without causing potential data loss or service disruption.

  • A. Incorrect.

    Deleting the S3 bucket immediately may result in data loss, which is not a recommended approach unless the data is not critical and you have a backup. This option does not align with best practices for mitigating security risks.

  • B. Correct.

    Updating the bucket policy to deny public access and enabling 'Block Public Access' settings is the most appropriate action to resolve the issue while maintaining security. This ensures the bucket is no longer publicly accessible and aligns with compliance standards.

  • C. Incorrect.

    Ignoring the finding is not a responsible action, as it fails to address the compliance issue and leaves the bucket publicly accessible, which could lead to security breaches.

  • D. Incorrect.

    While AWS Config rules can help enforce compliance, automatically deleting resources like S3 buckets could lead to unintended consequences, such as data loss or application failure. This is not a best practice for resolving the issue.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam