exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 2 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 2
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company is storing data in Amazon S3 Glacier. The security engineer implemented a new vault lock policy for 10TB of data and called initiate-vault-lock operation 12 hours ago. The audit team identified a typo in the policy that is allowing unintended access to the vault.
What is the MOST cost-effective way to correct this?

  • A. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again.
  • B. Copy the vault data to a new S3 bucket. Delete the vault. Create a new vault with the data.
  • C. Update the policy to keep the vault lock in place.
  • D. Update the policy. Call initiate-vault-lock operation again to apply the new policy.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 7 months, 4 weeks ago
A is correct answer.
upvoted 10 times
...
TollaMS
Highly Voted 3 years, 7 months ago
A is the answer https://docs.aws.amazon.com/amazonglacier/latest/dev/api-AbortVaultLock.html
upvoted 10 times
...
kjjcraigskel
Most Recent 7 months, 3 weeks ago
What can you do then if you've erroneously validated the lock ID and 24 hours have elapsed?
upvoted 1 times
...
RajaRaja
10 months, 1 week ago
Vault access policy is different from Vault lock policy. In this case, the options are not clear about which policy they are. Reading the question, it's about the access, so it appears if we update the vault access policy(which can be updated anytime) is more than sufficient. So I would go for C. Vault lock policy is primarily to avoid anyone deleting the object, it is not about un-intended access.
upvoted 1 times
...
Benah
1 year, 7 months ago
Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again
upvoted 1 times
...
KarthikeyanTK
1 year, 10 months ago
Selected Answer: D
In this scenario, you can simply update the existing policy with the correct configuration and call the initiate-vault-lock operation again to apply the updated policy. This allows you to rectify the typo and enforce the intended access controls without the need for additional data transfers or recreating the vault. Option A (calling abort-vault-lock and initiate-vault-lock again) would effectively remove the vault lock and reapply it with the correct policy, but it may incur additional costs and may not be as efficient as updating the policy directly.
upvoted 1 times
nand0l
1 year, 9 months ago
Sorry it is NOT possible to edit or udate the initiated vault-lock-policy without aborting it. so the correct answer is NOT D
upvoted 2 times
...
...
TCyberChef
1 year, 11 months ago
Selected Answer: A
The correct answer is: A. Call the abort-vault-lock operation. Update the policy. Call the initiate-vault-lock operation again. Explanation: The Amazon S3 Glacier vault lock policy allows you to deploy and enforce compliance controls for individual S3 Glacier vaults with a vault lock policy. Once you lock the policy, you can no longer change it. However, before the policy is locked, you can call the abort-vault-lock operation to stop the lock process, correct your policy, and then start the initiate-vault-lock operation again. This is the most cost-effective way because you won't incur data transfer costs or need to manage a new vault or bucket. Other options like copying data to a new bucket or updating the policy while keeping the vault lock in place are not possible once the vault lock is initiated.
upvoted 1 times
...
ITGURU51
1 year, 11 months ago
The most cost-effective way to correct the typo in the policy that is allowing unintended access to the vault is to call the **abort-vault-lock** operation, fix the typo in the policy and call the **initiate-vault-lock** operation again.
upvoted 1 times
...
KVK16
2 years, 3 months ago
Selected Answer: A
A direct update of vault policy and re-initiate Vault lock will fail with a AccesDenied Error as the lock is in-Progress Vault Lock stage and as 24 hrs is not yet completed. Even if invalid LockId is presented, it will return a Invalid parameter and continue in InProgress stage. If 24 hrs were not completed and Lock ID was provided it will enter Complete Vault-Lock state or if not provided it will automatically exit and the vault policy will be removed after 24 hrs. But this is risky as this is case of unintended access Other method is to initiate a AbortLock or Deletelock policy. Update the policy and initiate Vault Lock policy
upvoted 2 times
...
jishrajesh
2 years, 3 months ago
A is correct
upvoted 1 times
...
secdaddy
2 years, 3 months ago
Why not D ? It looks like the Initiate would auto revert without locking so no need to manually Abort before fixing the policy and re-Initiating lock ? "If you don't complete the Vault Lock process within 24 hours after entering the in-progress state, your vault automatically exits the in-progress state, and the Vault Lock policy is removed. You can call Initiate Vault Lock again to install a new Vault Lock policy and transition into the in-progress state." from the same URL
upvoted 1 times
...
gg12345
2 years, 5 months ago
Selected Answer: A
You have 24 hours to abort the lock after it's created. "If you don't complete the Vault Lock process within 24 hours after entering the in-progress state, your vault automatically exits the in-progress state, and the Vault Lock policy is removed. You can call Initiate Vault Lock again to install a new Vault Lock policy and transition into the in-progress state. The in-progress state provides the opportunity to test your Vault Lock policy before you lock it. Your Vault Lock policy takes full effect during the in-progress state just as if the vault has been locked, except that you can remove the policy by calling Abort Vault Lock (DELETE lock-policy). To fine-tune your policy, you can repeat the Abort Vault Lock/Initiate Vault Lock combination as many times as necessary to validate your Vault Lock policy changes."
upvoted 2 times
...
sapien45
2 years, 9 months ago
Selected Answer: A
To fine-tune your policy, you can repeat the Abort Vault Lock/Initiate Vault Lock combination as many times as necessary to validate your Vault Lock policy changes.
upvoted 1 times
...
NivNZ
3 years, 6 months ago
Answer: A https://docs.aws.amazon.com/amazonglacier/latest/dev/vault-lock-how-to-api.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago