A Company had a security event whereby an Amazon S3 bucket with sensitive information was made public. Company policy is to never have public S3 objects, and the Compliance team must be informed immediately when any public objects are identified. How can the presence of a public S3 object be detected, set to trigger alarm notifications, and automatically remediated in the future? (Choose two.)
A) Turn on object-level logging for Amazon S3. Turn on Amazon S3 event notifications to notify by using an Amazon SNS topic when a PutObject API call is made with a public-read permission. Turn on object-level logging for Amazon S3. Turn on Amazon S3 event notifications to notify by using an Amazon SNS topic when a PutObject API call is made with a public-read permission.
B) Configure an Amazon CloudWatch Events rule that invokes an AWS Lambda function to secure the S3 bucket.
C) Use the S3 bucket permissions for AWS Trusted Advisor and configure a CloudWatch event to notify by using Amazon SNS.
D) Turn on object-level logging for Amazon S3. Configure a CloudWatch event to notify by using an SNS topic when a PutObject API call with public-read permission is detected in the AWS CloudTrail logs. Turn on object-level logging for Amazon S3. Configure a CloudWatch event to notify by using an SNS topic when a API call with public-read permission is detected in the AWS CloudTrail logs.
E) Schedule a recursive Lambda function to regularly change all object permissions inside the S3 bucket.
Correct Answer:
Verified
Q405: A company is migrating to the cloud.
Q406: A company ingests and processes streaming market
Q407: A group of research institutions and hospitals
Q408: A company has developed a web application
Q409: A company that provides wireless services needs
Q411: A three-tier web application runs on Amazon
Q412: A company is finalizing the architecture for
Q413: The company Security team requires that all
Q414: A Solutions Architect must create a cost-effective
Q415: A company wants to ensure that the
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents