ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 47 - SCS-C01 discussion

Report
Export

A company has implemented centralized logging and monitoring of AWS CloudTrail logs from all Regions in an Amazon S3 bucket. The log Hies are encrypted using AWS KMS. A Security Engineer is attempting to review the log files using a third-party tool hosted on an Amazon EC2 instance The Security Engineer is unable to access the logs in the S3 bucket and receives an access denied error message What should the Security Engineer do to fix this issue?

A.
Check that the role the Security Engineer uses grants permission to decrypt objects using the KMS CMK.
Answers
A.
Check that the role the Security Engineer uses grants permission to decrypt objects using the KMS CMK.
B.
Check that the role the Security Engineer uses grants permission to decrypt objects using the KMS CMK and gives access to the S3 bucket and objects
Answers
B.
Check that the role the Security Engineer uses grants permission to decrypt objects using the KMS CMK and gives access to the S3 bucket and objects
C.
Check that the role the EC2 instance profile uses grants permission lo decrypt objects using the KMS CMK and gives access to the S3 bucket and objects
Answers
C.
Check that the role the EC2 instance profile uses grants permission lo decrypt objects using the KMS CMK and gives access to the S3 bucket and objects
D.
Check that the role the EC2 instance profile uses grants permission to decrypt objects using the KMS CMK
Answers
D.
Check that the role the EC2 instance profile uses grants permission to decrypt objects using the KMS CMK
Suggested answer: C
asked 16/09/2024
Nelson G Porras
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first