ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 41 - SCS-C02 discussion

Report
Export

A corporation is preparing to acquire several companies. A Security Engineer must design a solution to ensure that newly acquired IAM accounts follow the corporation's security best practices. The solution should monitor each Amazon S3 bucket for unrestricted public write access and use IAM managed services.

What should the Security Engineer do to meet these requirements?

A.
Configure Amazon Macie to continuously check the configuration of all S3 buckets.
Answers
A.
Configure Amazon Macie to continuously check the configuration of all S3 buckets.
B.
Enable IAM Config to check the configuration of each S3 bucket.
Answers
B.
Enable IAM Config to check the configuration of each S3 bucket.
C.
Set up IAM Systems Manager to monitor S3 bucket policies for public write access.
Answers
C.
Set up IAM Systems Manager to monitor S3 bucket policies for public write access.
D.
Configure an Amazon EC2 instance to have an IAM role and a cron job that checks the status of all S3 buckets.
Answers
D.
Configure an Amazon EC2 instance to have an IAM role and a cron job that checks the status of all S3 buckets.
Suggested answer: C

Explanation:

because this is a solution that can monitor each S3 bucket for unrestricted public write access and use IAM managed services. S3 is a service that provides object storage in the cloud. Systems Manager is a service that helps you automate and manage your AWS resources. You can use Systems Manager to monitor S3 bucket policies for public write access by using a State Manager association that runs a predefined document calledAWS-FindS3BucketWithPublicWriteAccess. This document checks each S3 bucket in an account and reports any bucket that has public write access enabled. The other options are either not suitable or not feasible for meeting the requirements.

asked 16/09/2024
Matthew Hillson
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first