exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 324 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 324
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A company needs to provide digital evidence to a security engineer for analysis. The evidence must be encrypted and the immutability of the source data must be maintained.
What is the MOST secure solution that meets these requirements?

  • A. Upload the digital evidence to a new Amazon S3 bucket. Set up an S3 Lifecycle configuration to move the data to S3 Glacier. Configure S3 Glacier with a vault lock policy.
  • B. Upload the digital evidence to a new Amazon S3 bucket with S3 Object Lock enabled. Implement server-side encryption with AWS Key Management Service (AWS KMS).
  • C. Upload the digital evidence to a new Amazon S3 bucket Configure an S3 bucket policy. Enable S3 Versioning and MFA Delete. Use S3 presigned URLs.
  • D. Launch an Amazon EC2 instance. Store the digital evidence on an attached Amazon Elastic Block Store (Amazon EBS) volume. Enable termination protection, isolate the EC2 instance and take a snapshot of the EBS volume.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Toptip
1 year, 11 months ago
Selected Answer: B
B encrypted and the immutability == kms + Object Lock
upvoted 1 times
...
ITGURU51
2 years ago
Object Lock provides two ways to manage object retention: retention periods and legal holds. Retention period — Specifies a fixed period of time during which an object remains locked. During this period, your object is WORM-protected and can't be overwritten or deleted. For more information, see Retention periods Legal hold — Provides the same protection as a retention period, but it has no expiration date. Instead, a legal hold remains in place until you explicitly remove it. Legal holds are independent from retention periods. For more information, see Legal holds. B
upvoted 1 times
...
sakibmas
2 years, 4 months ago
Selected Answer: B
With S3 Object Lock, you can store objects using a write-once-read-many (WORM) model. Object Lock can help prevent objects from being deleted or overwritten for a fixed amount of time or indefinitely. Reference: https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html
upvoted 1 times
ITGURU51
2 years ago
Uploading the digital evidence to a new Amazon S3 bucket with S3 Object Lock enabled and implementing server-side encryption with AWS Key Management Service (AWS KMS) would provide the necessary security and immutability for the digital evidence.
upvoted 1 times
...
...
HieuTT
2 years, 6 months ago
325 is the end question ??? While Database have 334 questions
upvoted 2 times
...
sapien45
2 years, 8 months ago
Selected Answer: B
With S3 Object Lock, you can store objects using a write-once-read-many (WORM) model. Object Lock can help prevent objects from being deleted or overwritten for a fixed amount of time or indefinitely. You can use Object Lock to help meet regulatory requirements that require WORM storage, or to simply add another layer of protection against object changes and deletion.
upvoted 4 times
...
MungKey
2 years, 8 months ago
B: https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-lock.html
upvoted 1 times
...
CuLeBrO
2 years, 8 months ago
B https://aws.amazon.com/about-aws/whats-new/2018/11/s3-object-lock/
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago