exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 265 discussion

A company stores sensitive data in an Amazon S3 bucket. The company encrypts the data at rest by using server-side encryption with Amazon S3 managed keys (SSE-S3).

A security engineer must prevent any modifications to the data in the S3 bucket.

Which solution will meet this requirement?

  • A. Configure S3 bucket policies to deny DELETE and PUT object permissions.
  • B. Configure S3 Object Lock in compliance mode with S3 bucket versioning enabled.
  • C. Change the encryption on the S3 bucket to use AWS Key Management Service (AWS KMS) customer managed keys.
  • D. Configure the S3 bucket with multi-factor authentication (MFA) delete protection.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Pmktechno
3 months, 4 weeks ago
Selected Answer: B
S3 Object Lock in compliance mode ensures that the objects cannot be deleted or overwritten for a fixed amount of time or indefinitely, providing a strong safeguard against accidental or malicious changes. Enabling versioning adds an additional layer of protection by keeping multiple versions of an object, which can be useful for recovery purposes.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago