ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 358 - SOA-C02 discussion

Report
Export

A company wants to store sensitive financial data within Amazon S3 buckets. The company has a corporate policy that does not allow public read or write access to the buckets. A SysOps administrator must create a solution to automatically remove S3 permissions that allow public read or write access.

Which AWS service should the SysOps administrator use to meet these requirements in the MOST operationally efficient manner?

A.
AWSConfig
Answers
A.
AWSConfig
B.
AWS Security Hub
Answers
B.
AWS Security Hub
C.
AWS Trusted Advisor
Answers
C.
AWS Trusted Advisor
D.
Amazon Inspector
Answers
D.
Amazon Inspector
Suggested answer: A

Explanation:

AWS Config is the best service to automatically manage and remediate S3 bucket permissions that violate corporate policies against public access. AWS Config continuously monitors and records AWS resource configurations and allows you to create rules that trigger automatic responses when public access configurations are detected. This approach is highly operationally efficient as it automates compliance and enforcement of security policies without manual intervention. Option A is correct. AWS Config can be used to assess, audit, and evaluate the configurations of AWS resources, including S3 buckets. Reference AWS Config.

asked 16/09/2024
NEURONES TECHNOLOGIES
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first