ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 480 - SCS-C01 discussion

Report
Export

A company is running workloads in a single AWS account on Amazon EC2 instances and Amazon EMR clusters a recent security audit revealed that multiple Amazon Elastic Block Store (Amazon EBS) volumes and snapshots are not encrypted The company's security engineer is working on a solution that will allow users to deploy EC2 Instances and EMR clusters while ensuring that all new EBS volumes and EBS snapshots are encrypted at rest. The solution must also minimize operational overhead Which steps should the security engineer take to meet these requirements?

A.
Create an Amazon Event Bridge (Amazon Cloud watch Events) event with an EC2 instance as the source and create volume as the event trigger. When the event is triggered invoke an AWS Lambda function to evaluate and notify the security engineer if the EBS volume that was created is not encrypted.
Answers
A.
Create an Amazon Event Bridge (Amazon Cloud watch Events) event with an EC2 instance as the source and create volume as the event trigger. When the event is triggered invoke an AWS Lambda function to evaluate and notify the security engineer if the EBS volume that was created is not encrypted.
B.
Use a customer managed IAM policy that will verify that the encryption flag of the Createvolume context is set to true. Apply this rule to all users.
Answers
B.
Use a customer managed IAM policy that will verify that the encryption flag of the Createvolume context is set to true. Apply this rule to all users.
C.
Create an AWS Config rule to evaluate the configuration of each EC2 instance on creation or modification. Have the AWS Config rule trigger an AWS Lambdafunction to alert the security team and terminate the instance it the EBS volume is not encrypted. 5
Answers
C.
Create an AWS Config rule to evaluate the configuration of each EC2 instance on creation or modification. Have the AWS Config rule trigger an AWS Lambdafunction to alert the security team and terminate the instance it the EBS volume is not encrypted. 5
D.
Use the AWS Management Console or AWS CLi to enable encryption by default for EBS volumes in each AWS Region where the company operates.
Answers
D.
Use the AWS Management Console or AWS CLi to enable encryption by default for EBS volumes in each AWS Region where the company operates.
Suggested answer: D
asked 16/09/2024
Lawrence Acherman
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first