Become Amazon Certified with updated SCS-C02 exam questions and correct answers
A company has a new web-based account management system for an online game Players create a unique username and password to log in to the system. The company has implemented an AWS WAF web ACL for the system. The web ACL includes the core rule set (CRS) AWS managed rule group on the Application Load Balancer that serves the system. The company's security team finds that the system was the target of a credential stuffing attack Credentials that were exposed in other breaches were used to try to log in to the system The security team must implement a solution to reduce the chance of a successful credential stuffing attack in the future The solution also must minimize impact on legitimate users of the system Which combination of actions will meet these requirements? (Select TWO.)
A security team is working on a solution that will use Amazon EventBridge (Amazon CloudWatch Events) to
monitor new Amazon S3 objects. The solution will monitor for public access and for changes to any S3 bucket
policy or setting that result in public access. The security team configures EventBridge to watch for specific
API calls that are logged from AWS CloudTrail. EventBridge has an action to send an email notification
through Amazon Simple Notification Service (Amazon SNS) to the security team immediately with details of
the API call.
Specifically, the security team wants EventBridge to watch for the s3:PutObjectAcl, s3:DeleteBucketPolicy,
and s3:PutBucketPolicy API invocation logs from CloudTrail. While developing the solution in a single
account, the security team discovers that the s3:PutObjectAcl API call does not invoke an EventBridge event.
However, the s3:DeleteBucketPolicy API call and the s3:PutBucketPolicy API call do invoke an event.
The security team has enabled CloudTrail for AWS management events with a basic configuration in the AWS
Region in which EventBridge is being tested. Verification of the EventBridge event pattern indicates that the
pattern is set up correctly. The security team must implement a solution so that the s3:PutObjectAcl API call
will invoke an EventBridge event. The solution must not generate false notifications.
Which solution will meet these requirements?
A developer who was recently fired by a company has a personal laptop that contains the SSH keys used to access multiple Amazon EC2 instances. The security team need to ensure the developer is unable to access the EC2 instances.How can a security engineer protect the running EC2 instances?
A company has a guideline that mandates the encryption of all Amazon S3 bucket data in transit. A security
engineer must implement an S3 bucket policy that denies any S3 operations if data is not encrypted.
Which S3 bucket policy will meet this requirement?
© Copyrights DumpsCertify 2025. All Rights Reserved
We use cookies to ensure your best experience. So we hope you are happy to receive all cookies on the DumpsCertify.