Medium1 markMultiple Choice
Domain 1.2: Security ControlsSecurityControl TowerS3

AWS SAP-C02 · Question 35 · Domain 1.2: Security Controls

A company has a multi-account environment managed by AWS Control Tower. They want to ensure that any Amazon S3 bucket created in any account automatically has AWS Key Management Service (AWS KMS) default encryption enabled. How can this be enforced centrally?

Answer options:

A.

Create an AWS Config rule in the management account.

B.

Enable the appropriate preventative guardrail (SCP) in AWS Control Tower.

C.

Use AWS CloudFormation StackSets to deploy a bucket policy to all accounts.

D.

Configure Amazon Macie to automatically encrypt unencrypted buckets.

How to approach this question

Identify the Control Tower feature used for preventative enforcement.

Full Answer

B.Enable the appropriate preventative guardrail (SCP) in AWS Control Tower.✓ Correct
AWS Control Tower uses guardrails to enforce policies. Preventative guardrails are implemented using Service Control Policies (SCPs) to ensure resources are created securely from the start.

Common mistakes

Choosing AWS Config, which only detects the issue after the bucket is created.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 1

75 questions · hints · full answers · grading

More questions from this exam