A developer operations team uses AWS Identity and Access Management (IAM) to manage user permissions. The team created an Amazon EC2 instance profile role that uses an AWS managed ReadOnlyAccess policy. When an application that is running on Amazon EC2 tries to read a file from an encrypted Amazon S3 bucket, the application receives an AccessDenied error.The team administrator has verified that the S3 bucket policy allows everyone in the account to access the S3 bucket. There is no object ACL that is attached to the file.What should the administrator do to fix the IAM access issue?
Answer(s): C
A company uses AWS Organizations and has Amazon Elastic Kubernetes Service (Amazon EKS) clusters in many AWS accounts. A security engineer integrates Amazon EKS with AWS CloudTrail. The CloudTrail trails are stored in an Amazon S3 bucket in each account to monitor API calls. The security engineer observes that CloudTrail logs are not displaying Kubernetes pod creation events.What should the security engineer do to view the Kubernetes events from Amazon CloudWatch?
Answer(s): B
A security engineer needs to build a solution to turn AWS CloudTrail back on in multiple AWS Regions in case it is ever turned off.What is the MOST efficient way to implement this solution?
Answer(s): A
An ecommerce company is developing new architecture for an application release. The company needs to implement TLS for incoming traffic to the application. Traffic for the application will originate from the internet. TLS does not have to be implemented in an end-to-end configuration because the company is concerned about impacts on performance The incoming traffic types will be HTTP and HTTPS The application uses ports 80 and 443.What should a security engineer do to meet these requirements?
Post your Comments and Discuss Amazon SCS-C02 exam with other Community members:
Mohammed Haque Commented on March 03, 2025 very useful site for exam prep UNITED STATES
Kevin Commented on January 03, 2025 Yo, just copped the full SCS-C02 material, and bro, it’s a lifesaver! AWS security is no joke, but this makes it way easier to get. If you’re tryna pass, don’t sleep on this, cuz it’s solid! UNITED STATES
Mosawar Commented on January 03, 2025 Passed this exam. Valid exam dumps. EUROPEAN UNION
Ahmad Commented on January 03, 2025 This test is hard. But questions in premium version is good and valid. Has screenshots from real exam scenarios. UNITED ARAB EMIRATES
Our website is free, but we have to fight against bots and content theft. We're sorry for the inconvenience caused by these security measures. You can access the rest of the SCS-C02 content, but please register or login to continue.