Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SCS-C02 Topic 8 Question 21 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 21
Topic #: 8
[All SCS-C02 Questions]

A company uses Amazon EC2 instances to host frontend services behind an Application Load Balancer. Amazon Elastic Block Store (Amazon EBS) volumes are attached to the EC2 instances. The company uses Amazon S3 buckets to store large files for images and music.

The company has implemented a security architecture oit>AWS to prevent, identify, and isolate potential ransomware attacks. The company now wants to further reduce risk.

A security engineer must develop a disaster recovery solution that can recover to normal operations if an attacker bypasses preventive and detective controls. The solution must meet an RPO of 1 hour.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: D

To ensure minimal latency and regional availability of secrets, encrypting secrets in us-east-1 with a customer-managed KMS key and then replicating them to us-west-1 for encryption with the same key is the optimal approach. This method leverages customer-managed KMS keys for enhanced control and ensures that secrets are available in both regions, adhering to disaster recovery principles and minimizing latency by using regional endpoints.


Contribute your Thoughts:

Earnestine
16 hours ago
Haha, D is like the 'nuclear option' - just blow away any infected instances and restore the latest snapshot. I wonder if that would actually work in a real-world scenario.
upvoted 0 times
...
Alba
4 days ago
I'm not a fan of B - relying on logs alone for automated response feels a bit risky. I'd prefer a solution that has more proactive recovery capabilities.
upvoted 0 times
...
Chara
18 days ago
I'm not sure, but option D also seems like a good choice with EBS snapshots every 4 hours and GuardDuty Malware Protection.
upvoted 0 times
...
Jess
19 days ago
I disagree, I believe option C is better as it uses Security Hub for recovery procedures and creates a centralized data lake for logs.
upvoted 0 times
...
Cyril
19 days ago
Option A seems like the most comprehensive solution, with regular backups and version control for the infrastructure. I like how it covers both EC2 and S3 components.
upvoted 0 times
...
Mari
26 days ago
I think option A is the best choice because it creates backups every hour and replicates the architecture components.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77