exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 243 discussion

A company maintains a large set of sensitive data in an Amazon S3 bucket. The company's security team asks a SysOps administrator to help verify that all current objects in the S3 bucket are encrypted.

What is the MOST operationally efficient solution that meets these requirements?

  • A. Create a script that runs against the S3 bucket and outputs the status of each object.
  • B. Create an S3 Inventory configuration on the S3 bucket. Include the appropriate status fields.
  • C. Provide the security team with an IAM user that has read access to the S3 bucket.
  • D. Use the AWS CLI to output a list of all objects in the S3 bucket.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Christina666
Highly Voted 9 months, 2 weeks ago
Selected Answer: B
You can use Amazon S3 Inventory to help manage your storage. For example, you can use it to audit and report on the replication and encryption status of your objects for business, compliance, and regulatory needs.
upvoted 5 times
jipark
8 months, 3 weeks ago
great !! - 'encryption status'
upvoted 1 times
...
...
hpipit
Most Recent 1 year, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
Vivec
1 year, 1 month ago
Selected Answer: B
The S3 Inventory feature provides a detailed report of objects and their metadata for an S3 bucket, which includes encryption status. By creating an S3 Inventory configuration on the S3 bucket and including the appropriate status fields, the security team can efficiently verify that all current objects in the S3 bucket are encrypted.
upvoted 2 times
...
braveheart22
1 year, 2 months ago
anderri is correct. B is the right answer.
upvoted 1 times
...
anderri
1 year, 2 months ago
Selected Answer: B
Encryption status – Set to SSE-S3, SSE-C, SSE-KMS, or NOT-SSE. The server-side encryption status for SSE-S3, SSE-KMS, and SSE with customer-provided keys (SSE-C). A status of NOT-SSE means that the object is not encrypted with server-side encryption. https://docs.aws.amazon.com/AmazonS3/latest/userguide/storage-inventory.html
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago