New Year Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

PDF SCS-C01 Study Guide

Page: 28 / 44
Total 589 questions

AWS Certified Security - Specialty Questions and Answers

Question 109

A windows machine in one VPC needs to join the AD domain in another VPC. VPC Peering has been established. But the domain join is not working. What is the other step that needs to be followed to ensure that the AD domain join can work as intended

Please select:

Options:

A.

Change the VPC peering connection to a VPN connection

B.

Change the VPC peering connection to a Direct Connect connection

C.

Ensure the security groups for the AD hosted subnet has the right rule for relevant subnets

D.

Ensure that the AD is placed in a public subnet

Question 110

Your company hosts critical data in an S3 bucket. There is a requirement to ensure that all data is encrypted. There is also metadata about the information stored in the bucket that needs to be encrypted as well. Which of the below measures would you take to ensure that the metadata is encrypted?

Please select:

Options:

A.

Put the metadata as metadata for each object in the S3 bucket and then enable S3 Server side encryption.

B.

Put the metadata as metadata for each object in the S3 bucket and then enable S3 Server KMS encryption.

C.

Put the metadata in a DynamoDB table and ensure the table is encrypted during creation time.

D.

Put thp metadata in thp S3 hurkpf itself.

Question 111

Your company is planning on using IAM EC2 and ELB for deployment for their web applications. The security policy mandates that all traffic should be encrypted. Which of the following options will ensure that this requirement is met. Choose 2 answers from the options below.

Please select:

Options:

A.

Ensure the load balancer listens on port 80

B.

Ensure the load balancer listens on port 443

C.

Ensure the HTTPS listener sends requests to the instances on port 443

D.

Ensure the HTTPS listener sends requests to the instances on port 80

Question 112

Your company has a requirement to work with a DynamoDB table. There is a security mandate that all data should be encrypted at rest. What is the easiest way to accomplish this for DynamoDB.

Please select:

Options:

A.

Use the IAM SDK to encrypt the data before sending it to the DynamoDB table

B.

Encrypt the DynamoDB table using KMS during its creation

C.

Encrypt the table using IAM KMS after it is created

D.

Use S3 buckets to encrypt the data before sending it to DynamoDB

Page: 28 / 44
Total 589 questions