AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial services company is designing a backup strategy for critical applications deployed across multiple accounts in an AWS Organization. The primary security requirement is to protect against ransomware that might compromise administrative credentials in the application accounts. The company needs to ensure that backups are immutable for a defined retention period and that a recovery path exists even if a source account is fully compromised. Which solution provides the MOST robust protection?

  • Deploy AWS Backup within each application account. Attach a strict permissions boundary to all administrative roles in the application accounts that explicitly denies actions like backup:DeleteRecoveryPoint and rds:DeleteDBSnapshot.

  • In each application account, configure AWS Backup to create snapshots. Use an AWS Lambda function to copy these snapshots to a central Amazon S3 bucket in a separate backup account. Apply an S3 Object Lock policy to the bucket to ensure immutability.

  • Designate a separate, hardened AWS account for backup administration. Use AWS Backup to centrally manage backup policies for member accounts. Configure backup plans to store backups in a vault within the administration account and enable AWS Backup Vault Lock in compliance mode. Replicate backups to a vault in a different AWS Region.

  • Use AWS Systems Manager Automation documents from a central account to run scripts that create EBS and RDS snapshots in each member account. Store a copy of the snapshot metadata in a central Amazon DynamoDB table and restrict access to the snapshots using resource-based policies.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot