Free SCS-C02 Exam Braindumps (page: 24)

Page 24 of 63

A company stores sensitive documents in Amazon S3 by using server-side encryption with an IAM Key Management Service (IAM KMS) CMK. A new requirement mandates that the CMK that is used for these documents can be used only for S3 actions.

Which statement should the company add to the key policy to meet this requirement?





Answer(s): A



A security engineer is defining the controls required to protect the IAM account root user credentials in an IAM Organizations hierarchy. The controls should also limit the impact in case these credentials have been compromised.

Which combination of controls should the security engineer propose? (Select THREE.)





  1. Enable multi-factor authentication (MFA) for the root user.
  2. Set a strong randomized password and store it in a secure location.
  3. Create an access key ID and secret access key, and store them in a secure location.
  4. Apply the following permissions boundary to the toot user:

Answer(s): A,C,E



A company is using IAM Organizations. The company wants to restrict IAM usage to the eu-west-1 Region for all accounts under an OU that is named "development." The solution must persist restrictions to existing and new IAM accounts under the development OU.






Answer(s): A



A company is undergoing a layer 3 and layer 4 DDoS attack on its web servers running on IAM.

Which combination of IAM services and features will provide protection in this scenario? (Select THREE).

  1. Amazon Route 53
  2. IAM Certificate Manager (ACM)
  3. Amazon S3
  4. IAM Shield.
  5. Elastic Load Balancer.
  6. Amazon GuardDuty.

Answer(s): D,E,F



Page 24 of 63



Post your Comments and Discuss Amazon SCS-C02 exam with other Community members:

Mohammed Haque commented on October 04, 2024
very useful site for exam prep
UNITED STATES
upvote