Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 259

    A company is planning to migrate its applications to AWS in a single AWS Region. The company’s applications will use a combination of Amazon EC2 instances, Elastic Load Balancing (ELB) load balancers, and Amazon S3 buckets. The company wants to complete the migration as quickly as possible. All the applications must meet the following requirements:

    • Data must be encrypted at rest. • Data must be encrypted in transit. • Endpoints must be monitored for anomalous network traffic.

    Which combination of steps should a security engineer take to meet these requirements with the LEAST effort?

    3 つ選択
    • Install the Amazon Inspector agent on EC2 instances by using AWS Systems Manager Automation.

    • Enable Amazon GuardDuty in all AWS accounts.

    • Create VPC endpoints for Amazon EC2 and Amazon S3. Update VPC route tables to use only the secure VPC endpoints.

    • Configure AWS Certificate Manager (ACM). Configure the load balancers to use certificates from ACM.

    • Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-meta-side-encryption.

    • Use AWS Key Management Service (AWS KMS) for key management. Create an S3 bucket policy to deny any PutObject command with a condition for x-amz-server-side-encryption.


    シャッフルモード