Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 337 discussion

A company runs applications in hundreds of production AWS accounts. The company uses AWS Organizations with all features enabled and has a centralized backup operation that uses AWS Backup.

The company is concerned about ransomware attacks. To address this concern, the company has created a new policy that all backups must be resilient to breaches of privileged-user credentials in any production account.

Which combination of steps will meet this new requirement? (Choose three.)

  • A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts.
  • B. Add an SCP that restricts the modification of AWS Backup vaults.
  • C. Implement AWS Backup Vault Lock in compliance mode.
    C. Implement least privilege access for the IAM service role that is assigned to AWS Backup.
  • D. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier.
  • E. Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled.
Show Suggested Answer Hide Answer
Suggested Answer: ACD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
devalenzuela86
Highly Voted 5 months, 4 weeks ago
Selected Answer: ACE
ACE for sure A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts. This will allow the company to securely copy their backups to other accounts that are part of their organization for operational or security reasons1. C. Implement AWS Backup Vault Lock in compliance mode. This will provide an additional layer of protection and immutability to the backup vaults, preventing any user (including the root user) or AWS from deleting or modifying the backups until the retention period is complete2. E. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier. This will help the company to avoid accidental or malicious deletion of backups by enforcing a minimum retention period and moving the backups to a lower-cost storage tier2.
upvoted 7 times
titi_r
1 month ago
A, C1, D you mean.
upvoted 1 times
...
tiagobs
5 months, 1 week ago
ACD you mean?
upvoted 4 times
...
...
ayadmawla
Highly Voted 5 months, 1 week ago
Selected Answer: ABC
The solution is A, B and C1. We need to create a Cross Account Backup -> Put it in a Backup Account -> Control modification to the backup account with SCP. A. Implement cross-account backup with AWS Backup vaults in designated non-production accounts. https://docs.aws.amazon.com/aws-backup/latest/devguide/manage-cross-account.html B. Add an SCP that restricts the modification of AWS Backup vaults. https://aws.amazon.com/blogs/storage/managing-access-to-backups-using-service-control-policies-with-aws-backup/ C1. Implement AWS Backup Vault Lock in compliance mode. https://docs.aws.amazon.com/aws-backup/latest/devguide/vault-lock.html
upvoted 5 times
...
seetpt
Most Recent 2 weeks, 1 day ago
Selected Answer: ABC
ABC For me
upvoted 1 times
...
hogtrough
2 months, 1 week ago
Selected Answer: ABC
ABC is definitely the answer. D. Configuring backup frequency does not do anything to prevent breaches E. AWS backup does not currently support S3 as a storage location for backups. You can use AWS backup to make a backup of S3 buckets but cannot use it to store backups.
upvoted 3 times
...
arberod
3 months ago
Selected Answer: ACD
ACD for sure
upvoted 2 times
...
chelbsik
3 months, 2 weeks ago
Selected Answer: ABC
ABC seems more reasonable over D(E) - as others mentioned, configuring backup doesn't protect from compromised creds attack. Moderator, please fix the answer letters order
upvoted 3 times
...
tmlong18
4 months ago
Selected Answer: ABC
ABC1 for sure
upvoted 4 times
...
vibzr2023
4 months, 1 week ago
Answer : ACC ( ACD).. there is typo in question second C should be D, D should be E, E should be F.. saying that the other options B. SCP restricting vault modification: Offers a good layer of protection, but doesn't directly address the concern of compromised credentials in production accounts. E. Cold Tier backups: Ensures backup accessibility in case of attacks, but doesn't specifically protect against compromised credentials. F. S3 Object Lock: Provides immutability within the non-production account, but if that account is breached, backups could still be compromised.
upvoted 3 times
...
career360guru
4 months, 1 week ago
Selected Answer: ACD
A, C, D
upvoted 2 times
...
bjexamprep
4 months, 2 weeks ago
Selected Answer: ABC
ABC are obvious correct. The question is why the rest of the answers are wrong. C. Implement least privilege access for the IAM service role that is assigned to AWS Backup. The question is looking for solution that survive privilege access breach. No matter how least privilege is granted, there must be other privilege users which can get more privileges. . D. Configure the backup frequency, lifecycle, and retention period to ensure that at least one backup always exists in the cold tier. Lifecycle doesn't prevent the backups to be deleted . E. Configure AWS Backup to write all backups to an Amazon S3 bucket in a designated non-production account. Ensure that the S3 bucket has S3 Object Lock enabled. AWS backup doesn't support S3 as the storage.
upvoted 3 times
...
water314
4 months, 2 weeks ago
Selected Answer: ABC
ABC for sure
upvoted 4 times
...
CProgrammer
4 months, 2 weeks ago
wait what ?? C. Implement AWS Backup Vault Lock in compliance mode. C. Implement least privilege access for the IAM service role that is assigned to AWS Backup.
upvoted 1 times
...
duriselvan
4 months, 3 weeks ago
https://aws.amazon.com/backup/faqs/
upvoted 1 times
...
duriselvan
4 months, 3 weeks ago
ACD ANS How does the AWS Backup lifecycle feature work? The AWS Backup lifecycle feature can automatically transition your recovery points from a warm storage tier to a lower-cost cold storage tier. Cold storage tier is available only for backups of EFS, DynamoDB, Timestream and VMware virtual machines.
upvoted 1 times
...
duriselvan
4 months, 3 weeks ago
How does the AWS Backup lifecycle feature work? The AWS Backup lifecycle feature can automatically transition your recovery points from a warm storage tier to a lower-cost cold storage tier. Cold storage tier is available only for backups of EFS, DynamoDB, Timestream and VMware virtual machines.
upvoted 1 times
...
blackgamer
5 months ago
The answer is ABC
upvoted 1 times
...
Russs99
5 months, 2 weeks ago
Selected Answer: ACD
While AWS Backup can be used to backup data stored in Amazon S3, it does not use S3 as a DataVaul, There option E is out
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...