exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 579 discussion

Exam question from Amazon's AWS-SysOps
Question #: 579
Topic #: 1
[All AWS-SysOps Questions]

InfoSec is concerned that an employee may expose sensitive data in an Amazon S3 bucket.
How can this concern be addressed without putting undue restrictions on users?

  • A. Apply an IAM policy on all users that denies the action s3:PutBucketPolicy
  • B. Restrict S3 bucket access to specific IAM roles managed using federated access
  • C. Activate an AWS Config rule to identify public buckets and alert InfoSec using Amazon SNS
  • D. Email the findings of AWS Personal Health Dashboard to InfoSec daily
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saumenP
Highly Voted 2 years, 6 months ago
C should be correct
upvoted 7 times
...
mukeshs
Highly Voted 2 years, 7 months ago
Ans B is restricting access to users. I think the answe should be C.
upvoted 7 times
...
albert_kuo
Most Recent 9 months, 4 weeks ago
Selected Answer: B
By restricting S3 bucket access to specific IAM roles, you can enforce fine-grained access control. This ensures that only authorized roles and users can interact with the S3 buckets. Federated access allows you to leverage external identity providers (such as Active Directory or SAML-based providers) to manage user access to AWS resources. This enables centralized access management and simplifies user onboarding and offboarding processes.
upvoted 1 times
albert_kuo
9 months, 4 weeks ago
Option C (activating an AWS Config rule to identify public buckets and alert InfoSec) is a good practice to detect public buckets, but it does not prevent the exposure of sensitive data. It provides notifications to InfoSec about public buckets but does not address the underlying issue of data exposure.
upvoted 1 times
...
...
TroyMcLure
2 years, 5 months ago
Correct Answer: C
upvoted 1 times
...
wshyang
2 years, 6 months ago
Why not C? https://aws.amazon.com/blogs/security/how-to-use-aws-config-to-monitor-for-and-respond-to-amazon-s3-buckets-allowing-public-access/
upvoted 3 times
...
karmaah
2 years, 6 months ago
Question : Putting Undue restriction. So A & B Not possible and D is not qualified answer. So Ans C
upvoted 6 times
...
kkwang
2 years, 7 months ago
C is the correct answer
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago