ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 186 - SOA-C02 discussion

Report
Export

A company updates its security policy to prohibit the public exposure of any data in Amazon S3 buckets in the company's account. What should a SysOps administrator do to meet this requirement?

A.
Turn on S3 Block Public Access from the account level.
Answers
A.
Turn on S3 Block Public Access from the account level.
B.
Create an Amazon EventBridge (Amazon CloudWatch Events) rule to enforce that all S3 objects are private.
Answers
B.
Create an Amazon EventBridge (Amazon CloudWatch Events) rule to enforce that all S3 objects are private.
C.
Use Amazon Inspector to search for S3 buckets and to automatically reset S3 ACLs if any public S3 buckets are found.
Answers
C.
Use Amazon Inspector to search for S3 buckets and to automatically reset S3 ACLs if any public S3 buckets are found.
D.
Use S3 Object Lambda to examine S3 ACLs and to change any public S3 ACLs to private.
Answers
D.
Use S3 Object Lambda to examine S3 ACLs and to change any public S3 ACLs to private.
Suggested answer: A

Explanation:

Using Amazon S3 Block Public Access as a centralized way to limit public access. Block Public Access settings override bucket policies and object permissions. Be sure to enable Block Public Access for all accounts and buckets that you don't want publicly accessible.

https://aws.amazon.com/premiumsupport/knowledge-center/secure-s3resources/#:~:text=Using%20Amazon%20S3%20Block%20Public,don't%20want%20publicly%20acces sible.

asked 16/09/2024
Michal Kopl
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first