New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 87 Topic 9 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 87 Topic 9 Discussion

SCS-C02 Exam Topic 9 Question 87 Discussion:
Question #: 87
Topic #: 9

A company stores sensitive data in an Amazon S3 bucket. The company encrypts the data at rest by using server-side encryption with Amazon S3 managed keys (SSE-S3). A security engineer must prevent any modifications to the data in the S3 bucket. Which solution will meet this requirement?


A.

Configure S3 bucket policies to deny DELETE and PUT object permissions.


B.

Configure S3 Object Lock in compliance mode with S3 bucket versioning enabled.


C.

Change the encryption on the S3 bucket to use AWS Key Management Service (AWS KMS) customer managed keys.


D.

Configure the S3 bucket with multi-factor authentication (MFA) delete protection.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.