Home › Forums › AWS › AWS Certified Security – Specialty › AWS Certified Security Specialty Practice Exam – Question Bank Updates
Tagged: kms
-
AWS Certified Security Specialty Practice Exam – Question Bank Updates
Joy-TutorialsDojo updated 3 days, 13 hours ago 9 Members · 49 Posts
-
This thread serves as a log of all the question bank updates and improvements that are incorporated into our practice test content on a regular basis.
P.S. Join our new Slack and Facebook groups to further foster the healthy discussions that we have here in the Tutorials Dojo Forums and in the Udemy Q&A sections. We’ll share helpful tips and insights about the AWS exams in these groups and they are publicly available so we encourage you to invite your colleagues and friends to join these groups as well.
Slack:
https://join.slack.com/t/tutorialsdojo/shared_invite/zt-f1zxo8lc-vKc1ZnJrSnE9OKFNR0g1hw
Facebook:
https://www.facebook.com/groups/awscertificationstalk/
Cheers,
Tutorials Dojo Team
-
Set 1
Minor update – Made some enhancements on one question’s options and explanation – “A Security Administrator prepared a new AWS Key Management Service (AWS KMS) key…”
-
Set 1
Minor update – Made some enhancements on one question’s scenario, options and explanation – “A company is using AWS Key Management Service (AWS KMS) to create and control various types…”
-
Please review the answer to “A financial company is using hundreds of Amazon S3 buckets to store sensitive corporate files. There is a requirement to improve the security of the data stored in S3 buckets. The files must be encrypted in transit and also at rest. Any object retrievals must be logged using AWS CloudTrail for audit purposes.”
I think one of the correct answers is incorrect. I found this while taking the Data Protection test. I’m happy to provide additional details offline; however, I do not want to spoil the question for others.
-
Thanks, Matt for bringing this up to our attention. Could you kindly share your thoughts on why the provided answer is incorrect?
Thanks in advance and Happy Holidays!
-
Hi Jon,
Thanks for the response. I guess it’s not so much that the answer is wrong; however, I feel that the option about the condition is only valid if it’s accompanied by the correct effect.
https://aws.amazon.com/premiumsupport/knowledge-center/s3-bucket-policy-for-config-rule/
Does that make sense?
Happy Holidays!
Matt
-
This reply was modified 2 years, 5 months ago by
matt-trevors.
-
This reply was modified 2 years, 5 months ago by
-
-
-
Seconded, I just took that sample series of questions and spent a long time considering the boolean:false before selecting what I felt was a less incorrect answer – versioning. The boolean condition would only be correct if the effect is deny, the way it’s written makes it feel like a distractor answer as there is no effect to determine if condition is applied?
-
Set 1
Minor update – Made some enhancements on one question’s scenario and explanation – “A Security Administrator created an Amazon S3 bucket policy that…”
Minor update – Made some enhancements on one question’s explanation – “A startup has a single AWS account that hosts its…”
-
Set 1
Minor update – Made some enhancements on one question’s option and explanation – “An organization is implementing a security policy in which their…”Set 2
Minor update – Made some enhancements on one question’s option and explanation – “A new security policy mandates that all communications between the…”
-
Set 2
Minor update – Made some enhancements on one question’s explanation – “A Security Engineer was assigned to manage the S3 bucket policies…”
-
Diagnostic test
Minor update – Made some enhancements on one question’s explanation – “A financial company is using hundreds of Amazon S3 buckets to…”
Set 2
Minor update – Made some enhancements on one question’s explanation – “A company wants to block all traffic to their Amazon S3 bucket…”
Log in to reply.