For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 24
    Hard1 markMultiple Choice
    Domain 2.3: Security ControlsSecurityData LakeLake FormationKMS

    AWS SAP-C02 · Question 24 · Domain 2.3: Security Controls

    A company is designing a data lake on Amazon S3. Data is ingested from various sources and processed by AWS Glue. The security team requires that all data be encrypted at rest using a customer-managed KMS key. Furthermore, access to the data must be strictly controlled based on user roles, and all data access must be audited. Which combination of services and configurations should be used? (Select THREE)

    Answer options:

    A.

    Configure S3 bucket policies to deny uploads unless encrypted with the specific KMS key.

    B.

    Use AWS Lake Formation to define fine-grained access controls at the database, table, and column levels.

    C.

    Enable AWS CloudTrail data events for the S3 buckets.

    D.

    Use Amazon Macie to enforce access controls based on data classification.

    E.

    Configure AWS IAM permissions boundaries on the S3 buckets.

    F.

    Use Amazon GuardDuty to encrypt the data at rest.

    How to approach this question

    Select the tools for encryption enforcement, fine-grained access, and auditing.

    Full Answer

    Configure S3 bucket policies to deny uploads unless encrypted with the specific KMS key., Use AWS Lake Formation to define fine-grained access controls at the database, table, and column levels., Enable AWS CloudTrail data events for the S3 buckets.
    S3 bucket policies enforce KMS encryption. Lake Formation provides fine-grained (column/row level) access control for data lakes. CloudTrail Data Events audit object-level access.

    Common mistakes

    Confusing Macie's discovery capabilities with access control enforcement.
    Question 23All questionsQuestion 25

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →