exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 337 discussion

A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup operation that uses AWS Backup.

The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.

Which combination of steps will meet this new requirement? (Choose three.)

  • A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
  • B. Add an SCP that restricts the modification of AWS Backup vaults.
  • C. Implement AWS Backup Vault Lock in compliance mode.
    C. Implement least privilege access for the IAM service role that is assigned to AWS Backup.
  • D. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier.
  • E. Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
Show Suggested Answer Hide Answer
Suggested Answer: ABC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ayadmawla
Highly Voted 1 year, 4 months ago
Selected Answer: ABC
The solution is A, B and C1. We need to create a Cross Account Backup -> Put it in a Backup Account -> Control modification to the backup account with SCP. A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts. https://docs.aws.amazon.com/aws-backup/latest/devguide/manage-cross-account.html B. Add an SCP that restricts the modification of AWS Backup vaults. https://aws.amazon.com/blogs/storage/managing-access-to-backups-using-service-control-policies-with-aws-backup/ C1. Implement AWS Backup Vault Lock in compliance mode. https://docs.aws.amazon.com/aws-backup/latest/devguide/vault-lock.html
upvoted 12 times
...
devalenzuela86
Highly Voted 1 year, 5 months ago
Selected Answer: ACE
ACE for sure A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts. This will allow the company to securely copy their backups to other accounts that are part of their organization for operational or security reasons1. C. Implement AWS Backup Vault Lock in compliance mode. This will provide an additional layer of protection and immutability to the backup vaults, preventing any user (including the root user) or AWS from deleting or modifying the backups until the retention period is complete2. E. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier. This will help the company to avoid accidental or malicious deletion of backups by enforcing a minimum retention period and moving the backups to a lower-cost storage tier2.
upvoted 8 times
titi_r
1 year ago
A, C1, D you mean.
upvoted 1 times
...
tiagobs
1 year, 4 months ago
ACD you mean?
upvoted 4 times
...
...
sashenka
Most Recent 5 months, 3 weeks ago
In a ransomware scenario where an attacker gains highly privileged access, both B and C2 can be bypassed. However, C2 (least privilege) offers a slightly stronger defense in this specific case. Here's why: If the attacker compromises an account with permissions to manage backups but not to manage SCPs, least privilege will still restrict their ability to delete or modify backups directly, even if they can't disable the SCP. An SCP, on the other hand, provides no additional protection if the attacker has the permissions to modify SCPs. The Verdict: While both B and C2 are important security practices, C2 (least privilege) is slightly better than B (SCPs) for mitigating the specific risk of ransomware attacks involving privileged credential compromise. However, neither is as effective as C1 (Vault Lock) and A (Cross-account backups).
upvoted 1 times
sashenka
5 months, 3 weeks ago
Please delete above. Correction to ABC
upvoted 1 times
...
...
Sin_Dan
6 months, 2 weeks ago
Selected Answer: BCD
Why would you store backup of a production environment in a non-production environment? That itself adds a security risk. And in my opinion removes options A and E from my choice. Also, option D it doesn't address the main concern. And options B, C and E look to solve the purpose effectively at least with the given choices and thus those are my choices.
upvoted 2 times
...
vip2
9 months, 3 weeks ago
Selected Answer: ACD
A C(C1) D are correct in questions.
upvoted 1 times
...
vip2
9 months, 3 weeks ago
Selected Answer: ACD
ACD are correct, that is A, C1 and D in question.
upvoted 1 times
...
Training
10 months, 1 week ago
Should be BCD. https://aws.amazon.com/blogs/storage/managing-access-to-backups-using-service-control-policies-with-aws-backup/ Cross-Account is not feasible. Hundreds of accounts.
upvoted 1 times
...
trungtd
10 months, 3 weeks ago
Selected Answer: ACD
A, C1, D B is incorrect: concern of compromised credentials: SCPs could potentially be modified by a user with sufficient privileges in the organization’s master account. C2: good for ensuring backup availability but does not directly address resilience against breaches of privileged-user credentials. E: provide similar benefits to using AWS Backup Vault Lock but is more complex to manage. AWS Backup Vault Lock is specifically designed for backup resilience and is more straightforward to implement within AWS Backup's framework.
upvoted 2 times
...
red_panda
11 months, 1 week ago
Selected Answer: ABC
A, B, C for me.
upvoted 2 times
...
sarlos
11 months, 1 week ago
ABC1 is the answer
upvoted 1 times
...
paderni
11 months, 1 week ago
A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts. C. Implement AWS Backup Vault Lock in compliance mode. E. Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
upvoted 1 times
...
seetpt
1 year ago
Selected Answer: ABC
ABC For me
upvoted 2 times
...
hogtrough
1 year, 1 month ago
Selected Answer: ABC
ABC is definitely the answer. D. Configuring backup frequency does not do anything to prevent breaches E. AWS backup does not currently support S3 as a storage location for backups. You can use AWS backup to make a backup of S3 buckets but cannot use it to store backups.
upvoted 6 times
...
arberod
1 year, 2 months ago
Selected Answer: ACD
ACD for sure
upvoted 3 times
...
chelbsik
1 year, 2 months ago
Selected Answer: ABC
ABC seems more reasonable over D(E) - as others mentioned, configuring backup doesn't protect from compromised creds attack. Moderator, please fix the answer letters order
upvoted 4 times
...
tmlong18
1 year, 3 months ago
Selected Answer: ABC
ABC1 for sure
upvoted 4 times
...
vibzr2023
1 year, 3 months ago
Answer : ACC ( ACD).. there is typo in question second C should be D, D should be E, E should be F.. saying that the other options B. SCP restricting vault modification: Offers a good layer of protection, but doesn't directly address the concern of compromised credentials in production accounts. E. Cold Tier backups: Ensures backup accessibility in case of attacks, but doesn't specifically protect against compromised credentials. F. S3 Object Lock: Provides immutability within the non-production account, but if that account is breached, backups could still be compromised.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago