nerdexam
Amazon

SAP-C02 · Question #682

A company has an application that stores data in a single Amazon S3 bucket. The company must keep all data for 1 year. The company's security team is concerned that an attacker could gain access to th

Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #682. The question stem and answer options stay visible for context.

Submitted by joshua94· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company has an application that stores data in a single Amazon S3 bucket. The company must keep all data for 1 year. The company's security team is concerned that an attacker could gain access to the AWS account through leaked long-term credentials. Which solution will ensure that existing and future objects in the S3 bucket are protected?

Options

  • ACreate a new AWS account that is accessible only to the security team through an assumed role.
  • BUse the s3-bucket-versioning-enabled AWS Config managed rule. Configure an automatic
  • CExplicitly deny bucket creation from all users and roles except for an AWS Service Catalog launch
  • DEnable Amazon GuardDuty with the S3 protection feature for the account and the AWS Region.

Unlock SAP-C02 to see the answer

You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SAP-C02 Practice