AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A large online retailer has hundreds of AWS accounts that are organized under AWS Organizations. Developers in non-production accounts sometimes upload production data that includes customer credit card numbers to Amazon S3. The security team must automatically detect any S3 object that contains credit card data in any account or Region, quarantine the object in an encrypted S3 bucket that only the security team can access, record each incident centrally for analyst review, and minimize custom code while adhering to least-privilege principles. Which approach will meet these requirements MOST effectively?

  • Enable Amazon Macie organization-wide automated sensitive-data discovery, publish Macie findings to AWS Security Hub and Amazon EventBridge, and configure an EventBridge rule that invokes an AWS Systems Manager Automation runbook to move the offending object to a centrally encrypted quarantine bucket and remove it from the source bucket.

  • Add an S3 event notification to every bucket that triggers a Lambda function with custom regular-expression logic to detect credit-card numbers; if detected, the function copies the object to a quarantine bucket and updates a DynamoDB table for reporting.

  • Enable Amazon GuardDuty with S3 Protection across the organization and configure the built-in quarantine action to move any object that triggers a GuardDuty finding to a secure S3 bucket.

  • Create an AWS Config managed rule package that evaluates whether S3 objects are encrypted with AWS KMS keys and sets an automatic remediation action to deny all access to any object that is not encrypted.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot