exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 6 discussion

A company must ensure that any objects uploaded to an S3 bucket are encrypted.
Which of the following actions will meet this requirement? (Choose two.)

  • A. Implement AWS Shield to protect against unencrypted objects stored in S3 buckets.
  • B. Implement Object access control list (ACL) to deny unencrypted objects from being uploaded to the S3 bucket.
  • C. Implement Amazon S3 default encryption to make sure that any object being uploaded is encrypted before it is stored.
  • D. Implement Amazon Inspector to inspect objects uploaded to the S3 bucket to make sure that they are encrypted.
  • E. Implement S3 bucket policies to deny unencrypted objects from being uploaded to the buckets.
Show Suggested Answer Hide Answer
Suggested Answer: CE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CVDON
Highly Voted 1 year, 12 months ago
C and E. S3 encryption and S3 bucket policy with deny S3 Put request whithout x-amz-server-side-encryption header
upvoted 9 times
mimahmed_awseducate
1 year, 2 months ago
Right Answer
upvoted 1 times
...
...
ogum
Most Recent 2 days, 3 hours ago
Selected Answer: CE
Answer is CE
upvoted 1 times
...
64rl0
5 months ago
Selected Answer: CE
Answer is CE
upvoted 1 times
...
NAVADIYA
1 year, 3 months ago
C. Implement Amazon S3 default encryption to make sure that any object being uploaded is encrypted before it is stored. Most Voted E. Implement S3 bucket policies to deny unencrypted objects from being uploaded to the buckets.
upvoted 2 times
...
CVDON
1 year, 12 months ago
https://aws.amazon.com/es/blogs/aws/amazon-s3-encrypts-new-objects-by-default/
upvoted 1 times
...
BietTuot
2 years, 2 months ago
Selected Answer: CE
C and E
upvoted 2 times
...
michaldavid
2 years, 2 months ago
ccc eee
upvoted 2 times
...
mlantonis2
2 years, 2 months ago
Selected Answer: CE
Ans: CE
upvoted 2 times
...
Liongeek
2 years, 2 months ago
Ans: CE
upvoted 1 times
...
Surferbolt
2 years, 4 months ago
Selected Answer: CE
C and E
upvoted 1 times
...
nakikoo
2 years, 5 months ago
CE correct, default encryption is a feature you can enable and disable in S3, it encrypt the data when entered S3 and decrypt whenever people retrieve data...server-side encryption is data encrypted as it is before entering an S3..
upvoted 1 times
...
MikeyJ
2 years, 8 months ago
Poorly worded question as encrypting objects before uploading would use client side encryption. C&E seem the most likely answers, as ACLs can't prevent the uploading of unencrypted objects.
upvoted 2 times
...
by116549
2 years, 9 months ago
Sorry @Finger41 and @Mecdrox I am bit confused by C as the question states: "verify that all items uploaded to an S3 bucket are encrypted prior to uploading them" Option C from what I can see states: "With Amazon S3 default encryption, you can set the default encryption behaviuor for an S3 bucket so that all new objects are encrypted when they are stored in the bucket. The objects are encrypted using server-side encryption with either Amazon S3-managed keys (SSE-S3) or AWS KMS keys stored in AWS Key Management Service (AWS KMS) (SSE-KMS)." https://docs.aws.amazon.com/AmazonS3/latest/userguide/bucket-encryption.html Does the data not need to be encrypted prior to being uploaded?
upvoted 1 times
Finger41
2 years, 8 months ago
Its encrypted at the time of writing to disk. :). Ensures all objects are encrypted when data is stored in S3, if using Amazon S3 default encryption ie server side encryption. Looking at an extension of your link : https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html Amazon S3 encrypts your data at the object level as it writes it to disks in its data centers and decrypts it for you when you access it.
upvoted 2 times
...
...
Finger41
2 years, 9 months ago
Selected Answer: CE
C & E - https://aws.amazon.com/blogs/security/how-to-prevent-uploads-of-unencrypted-objects-to-amazon-s3/
upvoted 3 times
MikeyJ
2 years, 8 months ago
"In order to enforce object encryption, create an S3 bucket policy that denies any S3 Put request that does not include the x-amz-server-side-encryption header. There are two possible values for the x-amz-server-side-encryption header: AES256, which tells S3 to use S3-managed keys, and aws:kms, which tells S3 to use AWS KMS–managed keys."
upvoted 1 times
...
...
Mecdrox
2 years, 9 months ago
Selected Answer: CE
C and E are correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago