A company runs workloads in the us-east-1 Region. The company has never deployed resources to other AWS Regions and does not have any multi-Region resources. The company needs to replicate its workloads and infrastructure to the us-west-1 Region.A security engineer must implement a solution that uses AWS Secrets Manager to store secrets in both Regions. The solution must use AWS Key Management Service (AWS KMS) to encrypt the secrets. The solution must minimize latency and must be able to work if only one Region is available.The security engineer uses Secrets Manager to create the secrets in us-east-1.What should the security engineer do next to meet the requirements?
Answer(s): D
A company is using an AWS Key Management Service (AWS KMS) AWS owned key in its application to encrypt files in an AWS account. The company's security team wants the ability to change to new key material for new files whenever a potential key breach occurs. A security engineer must implement a solution that gives the security team the ability to change the key whenever the team wants to do so.Which solution will meet these requirements?
Answer(s): C
A security engineer needs to set up an Amazon CloudFront distribution for an Amazon S3 bucket that hosts a static website. The security engineer must allow only specified IP addresses to access the website. The security engineer also must prevent users from accessing the website directly by using S3 URLs.Which solution will meet these requirements?
Answer(s): B
A company uses user data scripts that contain sensitive information to bootstrap Amazon EC2 instances. A security engineer discovers that this sensitive information is viewable by people who should not have access to it.What is the MOST secure way to protect the sensitive information used to bootstrap the instances?
Post your Comments and Discuss Amazon SCS-C02 exam with other Community members:
Mohammed Haque Commented on March 03, 2025 very useful site for exam prep UNITED STATES
Kevin Commented on January 03, 2025 Yo, just copped the full SCS-C02 material, and bro, it’s a lifesaver! AWS security is no joke, but this makes it way easier to get. If you’re tryna pass, don’t sleep on this, cuz it’s solid! UNITED STATES
Mosawar Commented on January 03, 2025 Passed this exam. Valid exam dumps. EUROPEAN UNION
Ahmad Commented on January 03, 2025 This test is hard. But questions in premium version is good and valid. Has screenshots from real exam scenarios. UNITED ARAB EMIRATES
Our website is free, but we have to fight against bots and content theft. We're sorry for the inconvenience caused by these security measures. You can access the rest of the SCS-C02 content, but please register or login to continue.