A Security Engineer is setting up an IAM CloudTrail trail for all regions in an IAM account.For added security, the logs are stored using server-side encryption with IAM KMS- managed keys (SSE-KMS) and have log integrity validation enabled.While testing the solution, the Security Engineer discovers that the digest files are readable, but the log files are not. What is the MOST likely cause?
Answer(s): B
Enabling server-side encryption encrypts the log files but not the digest files with SSE- KMS. Digest files are encrypted with Amazon S3-managed encryption keys (SSE-S3).
https://docs.IAM.amazon.com/IAMcloudtrail/latest/userguide/encrypting-cloudtrail-log-files- with-IAM-kms.html
A security engineer must develop an encryption tool for a company. The company requires a cryptographic solution that supports the ability to perform cryptographic erasure on all resources protected by the key material in 15 minutes or lessWhich IAM Key Management Service (IAM KMS) key solution will allow the security engineer to meet these requirements?
Answer(s): C
A company is running an application on Amazon EC2 instances in an Auto Scaling group. The application stores logs locally A security engineer noticed that logs were lost after ascale-in event. The security engineer needs to recommend a solution to ensure the durability and availability of log data All logs must be kept for a minimum of 1 year for auditing purposesWhat should the security engineer recommend?
Unapproved changes were previously made to a company's Amazon S3 bucket. A security engineer configured IAM Config to record configuration changes made to the company's S3 buckets. The engineer discovers there are S3 configuration changes being made, but no Amazon SNS notifications are being sent. The engineer has already checked the configuration of the SNS topic and has confirmed the configuration is valid.Which combination of steps should the security engineer take to resolve the issue? (Select TWO.)
Answer(s): B,E
A company's architecture requires that its three Amazon EC2 instances run behind an Application Load Balancer (ALB). The EC2 instances transmit sensitive data between each other Developers use SSL certificates to encrypt the traffic between the public users and the ALB However the Developers are unsure of how to encrypt the data in transit between the ALB and the EC2 instances and the traffic between the EC2 instancesWhich combination of activities must the company implement to meet its encryption requirements'? (Select TWO )
Answer(s): B,C
Post your Comments and Discuss Amazon AWS Certified Security-Specialty exam dumps with other Community members:
Anonymous Commented on July 31, 2025 Apparently option A for Question 216 was already sanitized? UNITED STATES
soma Commented on July 31, 2025 Dear Sir, I am interested for the exam dumps ITIL4 Foundation. If you sell it by 34 dollar I can buy. As I dont have any plan until I pass ITIL foundation, I cannot buy 2 with one free gift at 68 dollar. Please please please sell the exam dumps pdf at 34 dollar. GERMANY
Bhavya Sr Commented on July 31, 2025 These questions are really very useful and much effective to prepare for AWS-CP certification exam, i really appreciate the way these questions cover all the topics and being most effective resource for students Anonymous
Sasco Commented on July 31, 2025 This site is accurate UNITED STATES
ajlanemed Commented on July 31, 2025 thank you for your help ! SWITZERLAND
Anonny Commented on July 31, 2025 Will check after I complete Anonymous
Cindy Commented on July 31, 2025 SC-401 was definitely one of the tougher exams I’ve taken. The premium version of this exam dumps pdf exam dumps pdf really helped me pass. EUROPEAN UNION
Anonymous Commented on July 31, 2025 Helpful and realistic question exam dumps pdf for preparing for PSM1 exam. HONG KONG
yash Commented on July 31, 2025 this is nice set of questions which help on getting your topic understand more clearly Anonymous
LMB Commented on July 31, 2025 Question 55 is: NO YES YES GERMANY
Sanjay Commented on July 31, 2025 Awesome exam dump. Helped in the passing the exam Anonymous
Sanjay Commented on July 31, 2025 THis is awesome exam dump. It matched most of the questions in the exam Anonymous
Our website is free, but we have to fight against AI bots and content theft. We're sorry for the inconvenience caused by these security measures. You can access the rest of the AWS Certified Security-Specialty content, but please register or login to continue.