exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 383 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 383
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

What is the security best practice concerning sensitive data stored in Amazon S3?

  • A. Enable cross-Region replication on the S3 bucket.
  • B. Enable S3 server-side encryption on the S3 bucket.
  • C. Configure AWS WAF to prevent unauthorized access to the S3 bucket.
  • D. Configure Amazon GuardDuty to prevent unauthorized access to the S3 bucket.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Manny_75
1 year, 4 months ago
Selected Answer: B
Option D is not valid because: Amazon GuardDuty (Option D) is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It can detect issues related to S3 buckets, but it doesn't directly address the encryption of sensitive data in the bucket.
upvoted 1 times
...
Nolos
1 year, 6 months ago
Selected Answer: B
B. All Amazon S3 buckets have encryption configured by default, and all new objects that are uploaded to an S3 bucket are automatically encrypted at rest. Server-side encryption with Amazon S3 managed keys (SSE-S3) is the default encryption configuration for every bucket in Amazon S3. Why not D: Amazon GuardDuty is a threat detection service that continuously monitors your AWS accounts and workloads to detect malicious activity and delivers detailed security findings, enabling visibility and remediation. It's not a configurable filter to protect a S3 bucket
upvoted 1 times
Nolos
1 year, 6 months ago
Sources https://docs.aws.amazon.com/AmazonS3/latest/userguide/serv-side-encryption.html https://aws.amazon.com/pt/guardduty/#:~:text=How%20it%20works,findings%20for%20visibility%20and%20remediation.&text=This%20diagram%20details%20GuardDuty's%20features,AWS%20workload%20and%20resource%20types.
upvoted 1 times
...
...
fndslike
1 year, 8 months ago
Why not D. Configure Amazon GuardDuty to prevent unauthorized access to the S3 bucket.?
upvoted 4 times
Nolos
1 year, 6 months ago
Amazon GuardDuty is a threat detection service that continuously monitors your AWS accounts and workloads to detect malicious activity and delivers detailed security findings, enabling visibility and remediation. It's not a configurable filter to protect a S3 bucket.
upvoted 2 times
...
...
Pranava_GCP
1 year, 9 months ago
Selected Answer: B
B. Enable S3 server-side encryption on the S3 bucket. "Server-side encryption – When you use server-side encryption, Amazon S3 encrypts your objects before saving them on disks in its data centers and then decrypts the objects when you download them. Server-side encryption can help reduce risk to your data by encrypting the data with a key that is stored in a different mechanism than the mechanism that stores the data itself." https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html#:~:text=Server%2Dside%20encryption%20%E2%80%93%20When,stores%20the%20data%20itself.
upvoted 2 times
...
Guru4Cloud
2 years ago
Selected Answer: B
The best practice for securing sensitive data stored in Amazon S3 is to enable S3 server-side encryption on the S3 bucket. This ensures that the data is encrypted at rest and can only be accessed by authorized parties with the appropriate decryption keys.
upvoted 3 times
...
RajithaR
2 years, 1 month ago
Selected Answer: B
B. Enable S3 server-side encryption on the S3 bucket. Enabling server-side encryption ensures that sensitive data stored in Amazon S3 is protected at rest, even if an unauthorized party gains access to the data. It also helps meet compliance requirements for data protection. Cross-Region replication, AWS WAF, and Amazon GuardDuty are all useful for enhancing the security of an S3 bucket, but enabling server-side encryption is a fundamental security best practice.
upvoted 3 times
...
Saif93
2 years, 3 months ago
Selected Answer: B
B is the answer.
upvoted 2 times
...
Vrush44
2 years, 4 months ago
Selected Answer: B
Guradduty is threat detection service that will monitor and provide detailed findings on malicious activities for remediation. for sensitive data handling, s3 server side encryption seems to be more accurate option.
upvoted 3 times
...
FreddyBrainy
2 years, 5 months ago
Correct Answer B. Server side encryption. Forgive my initial response. Thank you.
upvoted 3 times
...
Redes
2 years, 5 months ago
Answer B
upvoted 3 times
...
simonak
2 years, 5 months ago
Selected Answer: B
B os correct, yes
upvoted 3 times
...
SLEON01
2 years, 5 months ago
Selected Answer: B
B, best option, that way owner has encryption keys
upvoted 2 times
...
JA2018
2 years, 5 months ago
Selected Answer: B
Should be B Security Best Practices for Amazon S3 https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
upvoted 4 times
...
FreddyBrainy
2 years, 5 months ago
Answer D is correct in my opinion.
upvoted 1 times
...
simonak
2 years, 5 months ago
Selected Answer: A
A is correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago