Hard1 markMultiple Choice
Domain 2.3: Security ControlsSecurityData LakeLake FormationKMS

AWS SAP-C02 · Question 24 · Domain 2.3: Security Controls

A company is designing a data lake on Amazon S3. Data is ingested from various sources and processed by AWS Glue. The security team requires that all data be encrypted at rest using a customer-managed KMS key. Furthermore, access to the data must be strictly controlled based on user roles, and all data access must be audited. Which combination of services and configurations should be used? (Select THREE)

Answer options:

A.

Configure S3 bucket policies to deny uploads unless encrypted with the specific KMS key.

B.

Use AWS Lake Formation to define fine-grained access controls at the database, table, and column levels.

C.

Enable AWS CloudTrail data events for the S3 buckets.

D.

Use Amazon Macie to enforce access controls based on data classification.

E.

Configure AWS IAM permissions boundaries on the S3 buckets.

F.

Use Amazon GuardDuty to encrypt the data at rest.

How to approach this question

Select the tools for encryption enforcement, fine-grained access, and auditing.

Full Answer

S3 bucket policies enforce KMS encryption. Lake Formation provides fine-grained (column/row level) access control for data lakes. CloudTrail Data Events audit object-level access.

Common mistakes

Confusing Macie's discovery capabilities with access control enforcement.

Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

75 questions · hints · full answers · grading

More questions from this exam