Amazon
SAP-C02 · Question #682
A company has an application that stores data in a single Amazon S3 bucket. The company must keep all data for 1 year. The company's security team is concerned that an attacker could gain access to th
Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #682. The question stem and answer options stay visible for context.
Submitted by joshua94· Mar 6, 2026Design Solutions for Organizational Complexity
Question
A company has an application that stores data in a single Amazon S3 bucket. The company must keep all data for 1 year. The company's security team is concerned that an attacker could gain access to the AWS account through leaked long-term credentials. Which solution will ensure that existing and future objects in the S3 bucket are protected?
Options
- ACreate a new AWS account that is accessible only to the security team through an assumed role.
- BUse the s3-bucket-versioning-enabled AWS Config managed rule. Configure an automatic
- CExplicitly deny bucket creation from all users and roles except for an AWS Service Catalog launch
- DEnable Amazon GuardDuty with the S3 protection feature for the account and the AWS Region.
Unlock SAP-C02 to see the answer
You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.