AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your company must comply with a security mandate that forbids public read or write access to any Amazon S3 bucket. The operations team wants a fully managed, code-free solution that will 1) detect every time a bucket becomes publicly accessible and 2) immediately remove that public access. Which approach meets these requirements with the LEAST operational overhead?

  • Create the AWS Config managed rules S3_BUCKET_PUBLIC_READ_PROHIBITED and S3_BUCKET_PUBLIC_WRITE_PROHIBITED, associate each rule with the Systems Manager Automation runbook AWS-DisableS3BucketPublicReadWrite, and enable automatic remediation for the rules.

  • Enable Amazon Macie inventory monitoring on all buckets and configure Macie to automatically enable S3 Block Public Access whenever it generates a policy finding for a public bucket.

  • Enable AWS CloudTrail and configure an Amazon EventBridge rule to invoke a Lambda function whenever PutBucketAcl or PutBucketPolicy is called; have the function apply S3 Block Public Access settings to the affected bucket.

  • Add the AWS Config managed rule S3_BUCKET_LEVEL_PUBLIC_ACCESS_PROHIBITED, set it to run periodic evaluations only, and configure it to publish an Amazon SNS notification so engineers can manually run the AWS-DisableS3BucketPublicReadWrite runbook when a bucket is NON_COMPLIANT.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot