ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 212 - SAP-C02 discussion

Report
Export

A company needs to audit the security posture of a newly acquired AWS account. The company's data security team requires a notification only when an Amazon S3 bucket becomes publicly exposed. The company has already established an Amazon Simple Notification Service (Amazon SNS) topic that has the data security team's email address subscribed.

Which solution will meet these requirements?

A.
Create an S3 event notification on all S3 buckets for the isPublic event. Select the SNS topic as the target for the event notifications.
Answers
A.
Create an S3 event notification on all S3 buckets for the isPublic event. Select the SNS topic as the target for the event notifications.
B.
Create an analyzer in AWS Identity and Access Management Access Analyzer. Create an Amazon EventBridge rule for the event type ''Access Analyzer Finding'' with a filter for ''isPublic: true.'' Select the SNS topic as the EventBridge rule target.
Answers
B.
Create an analyzer in AWS Identity and Access Management Access Analyzer. Create an Amazon EventBridge rule for the event type ''Access Analyzer Finding'' with a filter for ''isPublic: true.'' Select the SNS topic as the EventBridge rule target.
C.
Create an Amazon EventBridge rule for the event type ''Bucket-Level API Call via CloudTrail'' with a filter for ''PutBucketPolicy.'' Select the SNS topic as the EventBridge rule target.
Answers
C.
Create an Amazon EventBridge rule for the event type ''Bucket-Level API Call via CloudTrail'' with a filter for ''PutBucketPolicy.'' Select the SNS topic as the EventBridge rule target.
D.
Activate AWS Config and add the cloudtrail-s3-dataevents-enabled rule. Create an Amazon EventBridge rule for the event type ''Config Rules Re-evaluation Status'' with a filter for ''NON_COMPLIANT.'' Select the SNS topic as the EventBridge rule target.
Answers
D.
Activate AWS Config and add the cloudtrail-s3-dataevents-enabled rule. Create an Amazon EventBridge rule for the event type ''Config Rules Re-evaluation Status'' with a filter for ''NON_COMPLIANT.'' Select the SNS topic as the EventBridge rule target.
Suggested answer: B

Explanation:

Access Analyzer is to assess the access policy. https://docs.aws.amazon.com/ja_jp/AmazonS3/latest/userguide/access-control-block-public-access.html

asked 16/09/2024
William Hanna
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first