AWS Certified Solutions Architect Professional SAP-C02 Practice Question
A financial services company is designing a backup strategy for critical applications deployed across multiple accounts in an AWS Organization. The primary security requirement is to protect against ransomware that might compromise administrative credentials in the application accounts. The company needs to ensure that backups are immutable for a defined retention period and that a recovery path exists even if a source account is fully compromised. Which solution provides the MOST robust protection?
Use AWS Systems Manager Automation documents from a central account to run scripts that create EBS and RDS snapshots in each member account. Store a copy of the snapshot metadata in a central Amazon DynamoDB table and restrict access to the snapshots using resource-based policies.
In each application account, configure AWS Backup to create snapshots. Use an AWS Lambda function to copy these snapshots to a central Amazon S3 bucket in a separate backup account. Apply an S3 Object Lock policy to the bucket to ensure immutability.
Deploy AWS Backup within each application account. Attach a strict permissions boundary to all administrative roles in the application accounts that explicitly denies actions like backup:DeleteRecoveryPoint and rds:DeleteDBSnapshot.
Designate a separate, hardened AWS account for backup administration. Use AWS Backup to centrally manage backup policies for member accounts. Configure backup plans to store backups in a vault within the administration account and enable AWS Backup Vault Lock in compliance mode. Replicate backups to a vault in a different AWS Region.
The correct answer describes a multi-layered, best-practice approach for ransomware resilience. Designating a separate, hardened AWS account as a backup archive and delegating it for backup administration isolates the backups from the source application accounts. Using AWS Backup to centrally manage policies across the AWS Organization simplifies governance. Storing backups in a vault within this central account, and then enabling AWS Backup Vault Lock in compliance mode, makes the recovery points immutable. Once locked in compliance mode, no user, including the root user, can alter or delete the recovery points before the retention period expires, providing strong protection against malicious or accidental deletion. Finally, replicating the backups to another vault in a different AWS Region provides disaster recovery capabilities.
Using AWS Backup within each account and attaching a permissions boundary is insufficient because a compromised administrative user in the source account could potentially modify or remove the IAM boundary, nullifying the protection. The backups are not sufficiently isolated.
Using custom scripts managed by Systems Manager is operationally complex and lacks the built-in immutability and governance features of AWS Backup Vault Lock. This approach is more prone to misconfiguration and does not provide the same level of security as a managed service designed for this purpose.
A solution using Lambda to copy snapshots to an S3 bucket with Object Lock is a viable but less integrated approach. It creates more operational overhead and complexity in managing permissions and the entire backup lifecycle compared to the native, fully managed cross-account capabilities of AWS Backup.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Backup Vault Lock, and how does it ensure immutability?
Open an interactive chat with Bash
Why is it important to use a separate hardened account for backup administration?
Open an interactive chat with Bash
How does replicating backups to another AWS Region improve disaster recovery?
Open an interactive chat with Bash
AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .