ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 32 - SCS-C01 discussion

Report
Export

A company is using AWS Organizations to manage multiple AWS accounts. The company has an application that allows users to assume the AppUser IAM role to download files from an Amazon S3 bucket that is encrypted with an AWS KMS CMK However when users try to access the files in the S3 bucket they get an access denied error.

What should a Security Engineer do to troubleshoot this error? (Select THREE )

A.
Ensure the KMS policy allows the AppUser role to have permission to decrypt for the CMK
Answers
A.
Ensure the KMS policy allows the AppUser role to have permission to decrypt for the CMK
B.
Ensure the S3 bucket policy allows the AppUser role to have permission to get objects for the S3 bucket
Answers
B.
Ensure the S3 bucket policy allows the AppUser role to have permission to get objects for the S3 bucket
C.
Ensure the CMK was created before the S3 bucket.
Answers
C.
Ensure the CMK was created before the S3 bucket.
D.
Ensure the S3 block public access feature is enabled for the S3 bucket.
Answers
D.
Ensure the S3 block public access feature is enabled for the S3 bucket.
E.
Ensure that automatic key rotation is disabled for the CMK
Answers
E.
Ensure that automatic key rotation is disabled for the CMK
F.
Ensure the SCPs within Organizations allow access to the S3 bucket.
Answers
F.
Ensure the SCPs within Organizations allow access to the S3 bucket.
Suggested answer: A, B, F
asked 16/09/2024
Matthew Farrington
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first