Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 17 Topic 2 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 17 Topic 2 Discussion

SCS-C03 Exam Topic 2 Question 17 Discussion:
Question #: 17
Topic #: 2

A company’s security engineer receives an alert that indicates that an unexpected principal is accessing a company-owned Amazon Simple Queue Service (Amazon SQS) queue. All the company’s accounts are within an organization in AWS Organizations. The security engineer must implement a mitigation solution that minimizes compliance violations and investment in tools outside of AWS.

What should the security engineer do to meet these requirements?


A.

Create security groups and attach them to all SQS queues.


B.

Modify network ACLs in all VPCs to restrict inbound traffic.


C.

Create interface VPC endpoints for Amazon SQS. Restrict access using aws:SourceVpce and aws:PrincipalOrgId conditions.


D.

Use a third-party cloud access security broker (CASB).


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.