New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 14 Topic 2 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 14 Topic 2 Discussion

SCS-C03 Exam Topic 2 Question 14 Discussion:
Question #: 14
Topic #: 2

A company has AWS accounts in an organization in AWS Organizations. An Amazon S3 bucket in one account is publicly accessible. A security engineer must remove public access and ensure the bucket cannot be made public again.

Which solution will meet these requirements?


A.

Enforce KMS encryption and deny s3:GetObject by SCP.


B.

Enable PublicAccessBlock and deny s3:GetObject by SCP.


C.

Enable PublicAccessBlock and deny s3:PutPublicAccessBlock by SCP.


D.

Enable Object Lock governance and deny s3:PutPublicAccessBlock by SCP.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.