Skip to content
Tip 2 Cloud

Learn & move to cloud

SCS-C01 (Page 16)

What should the security engineer do to meet this requirement?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company’s data is encrypted in an Amazon S3 bucket by an AWS Key Management Service (AWS KMS) customer managed key.The company has AWS Lambda functions that run in the same account as the S3 bucket.The Lambda functions need to access the data in the S3 bucket.A security engineer must ensure that each Lambda function has its own programmatic access control permissions to use the KMS key.What should the security engineer do to meet this requirement?Read More →

Which solution will meet these requirements with the LEAST operational overhead?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company is designing a multi-account structure for its development teams.The company is using AWS Organizations and AWS Single Sign-On (AWS SSO).The company must implement a solution so that the development teams can use only specific AWS Regions and so that each AWS account allows access to only specific AWS services.Which solution will meet these requirements with the LEAST operational overhead?Read More →

Which solution will meet this requirement?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company is using AWS Organizations to create OUs for its accounts.The company has more than 20 accounts that are all part of the OUs.A security engineer must implement a solution to ensure that no account can stop log file delivery to AWS CloudTrail.Which solution will meet this requirement?Read More →

Which solution will meet these requirements with the LEAST management overhead?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company is using Amazon Elastic Container Service (Amazon ECS) to run its container-based application on AWS.The company needs to ensure that the container images contain no severe vulnerabilities.The company also must ensure that only specific IAM roles and specific AWS accounts can access the container images.Which solution will meet these requirements with the LEAST management overhead?Read More →

What should a security engineer do to meet this requirement?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company plans to use AWS CodeDeploy to deploy code to multiple Amazon EC2 instances in a VPC at the same time.The company needs to allow the CodeDeploy service to communicate with the instances in the VPC without going through the public internet for CodeDeploy API operations.What should a security engineer do to meet this requirement?Read More →

Which combination of actions would build the required solution?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company has several production AWS accounts and a central security AWS account.The security account is used for centralized monitoring and has IAM privileges to all resources in every corporate account.All of the company’s Amazon S3 buckets are tagged with a value denoting the data classification of their contents.A Security Engineer is deploying a monitoring solution in the security account that will enforce bucket policy compliance.The system must monitor S3 buckets in all production accounts and confirm that any policy change is in accordance with the bucket’s data classification.If any change is out of compliance, the Security team must be notified quickly.Which combination of actions would build the required solution? (Choose three.)Read More →

What should the Security Engineer do to meet these requirements?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

An organization wants to deploy a three-tier web application whereby the application servers run on Amazon EC2 instances.These EC2 instances need access to credentials that they will use to authenticate their SQL connections to an Amazon RDS DB instance.Also, AWS Lambda functions must issue queries to the RDS database by using the same database credentials.The credentials must be stored so that the EC2 instances and the Lambda functions can access them.No other access is allowed.The access logs must record when the credentials were accessed and by whom.What should the Security Engineer do to meet these requirements?Read More →

Which solution will meet these requirements with the LEAST operational overhead?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company is running its workloads in a single AWS Region and uses AWS Organizations.A security engineer must implement a solution to prevent users from launching resources in other Regions.Which solution will meet these requirements with the LEAST operational overhead?Read More →

Which combination of steps should the Administrator take to troubleshoot this issue?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

An application makes calls to AWS services using the AWS SDK.The application runs on Amazon EC2 instances with an associated IAM role.When the application attempts to access an object within an Amazon S3 bucket; the Administrator receives the following error message: HTTP 403: Access Denied.Which combination of steps should the Administrator take to troubleshoot this issue? (Choose three.)Read More →

Which steps must be taken to address this situation?

2025-01-10
By: study aws cloud
On: January 10, 2025
In: SCS-C01
With: 0 Comments

A company stores data on an Amazon EBS volume attached to an Amazon EC2 instance.The data is asynchronously replicated to an Amazon S3 bucket.Both the EBS volume and the S3 bucket are encrypted with the same AWS KMS Customer Master Key (CMK).A former employee scheduled a deletion of that CMK before leaving the company.The company’s Developer Operations department learns about this only after the CMK has been deleted.Which steps must be taken to address this situation?Read More →

Posts pagination

Previous 1 … 15 16 17 … 41 Next

Recent Posts

  • Which of the below mentioned statements helps the user disable connection draining on the ELB?
  • What change should the SysOps Administrator make to the company’s existing AWS setup to achieve this result?
  • How can the user configure this?
  • How can the user achieve DR?
  • What two actions could you take to rectify this?

Categories

  • CLF-C01
  • CLF-C02
  • DBS-C01
  • DOP-C01
  • DOP-C02
  • DVA-C01
  • DVA-C02
  • MLS-C01
  • SAA-C02
  • SAA-C03
  • SAP-C01
  • SAP-C02
  • SCS-C01
  • SOA-C01
  • SOA-C02

© 2025. Tip2Cloud doesn't offer any real exam questions. All questions & answers were supported by AI.