ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 185 - DOP-C02 discussion

Report
Export

A company has a new AWS account that teams will use to deploy various applications. The teams will create many Amazon S3 buckets for application- specific purposes and to store AWS CloudTrail logs. The company has enabled Amazon Macie for the account.

A DevOps engineer needs to optimize the Macie costs for the account without compromising the account's functionality.

Which solutions will meet these requirements? (Select TWO.)

A.
Exclude S3 buckets that contain CloudTrail logs from automated discovery.
Answers
A.
Exclude S3 buckets that contain CloudTrail logs from automated discovery.
B.
Exclude S3 buckets that have public read access from automated discovery.
Answers
B.
Exclude S3 buckets that have public read access from automated discovery.
C.
Configure scheduled daily discovery jobs for all S3 buckets in the account.
Answers
C.
Configure scheduled daily discovery jobs for all S3 buckets in the account.
D.
Configure discovery jobs to include S3 objects based on the last modified criterion.
Answers
D.
Configure discovery jobs to include S3 objects based on the last modified criterion.
E.
Configure discovery jobs to include S3 objects that are tagged as production only.
Answers
E.
Configure discovery jobs to include S3 objects that are tagged as production only.
Suggested answer: A, D

Explanation:

To optimize the Macie costs for the account without compromising the account's functionality, the DevOps engineer needs to exclude S3 buckets that do not contain sensitive data from automated discovery. S3 buckets that contain CloudTrail logs are unlikely to have sensitive data, and Macie charges for scanning and monitoring data in S3 buckets. Therefore, excluding S3 buckets that contain CloudTrail logs from automated discovery can reduce Macie costs. Similarly, configuring discovery jobs to include S3 objects based on the last modified criterion can also reduce Macie costs, as it will only scan and monitor new or updated objects, rather than all objects in the bucket.

asked 16/09/2024
john rosselot
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first