New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Ace Your SCS-C01 AWS Certified Specialty Exam

Page: 31 / 44
Total 589 questions

AWS Certified Security - Specialty Questions and Answers

Question 121

Your company has an external web site. This web site needs to access the objects in an S3 bucket. Which of the following would allow the web site to access the objects in the most secure manner?

Please select:

Options:

A.

Grant public access for the bucket via the bucket policy

B.

Use the IAM:Referer key in the condition clause for the bucket policy

C.

Use the IAM:sites key in the condition clause for the bucket policy

D.

Grant a role that can be assumed by the web site

Question 122

There is a set of Ec2 Instances in a private subnet. The application hosted on these EC2 Instances need to access a DynamoDB table. It needs to be ensured that traffic does not flow out to the internet. How can this be achieved?

Please select:

Options:

A.

Use a VPC endpoint to the DynamoDB table

B.

Use a VPN connection from the VPC

C.

Use a VPC gateway from the VPC

D.

Use a VPC Peering connection to the DynamoDB table

Question 123

Your company has created a set of keys using the IAM KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used only for the S3 service. How can this be achieved?

Please select:

Options:

A.

Create an IAM policy that allows the key to be accessed by only the S3 service.

B.

Create a bucket policy that allows the key to be accessed by only the S3 service.

C.

Use the kms:ViaService condition in the Key policy

D.

Define an IAM user, allocate the key and then assign the permissions to the required service

Question 124

You are planning to use IAM Configto check the configuration of the resources in your IAM account. You are planning on using an existing IAM role and using it for the IAM Config resource. Which of the following is required to ensure the IAM config service can work as required?

Please select:

Options:

A.

Ensure that there is a trust policy in place for the IAM Config service within the role

B.

Ensure that there is a grant policy in place for the IAM Config service within the role

C.

Ensure that there is a user policy in place for the IAM Config service within the role

D.

Ensure that there is a group policy in place for the IAM Config service within the role

Page: 31 / 44
Total 589 questions