Amazon AWS-CERTIFIED-BIG-DATA-SPECIALTY AWS-Certified-Big-Data-Specialty Dumps in PDF

Free Amazon AWS-Certified-Big-Data-Specialty Real Questions (page: 16)

What does the Server-side encryption provide in Amazon S3?

  1. Server-side encryption protects data at rest using Amazon S3-managed encryption keys (SSE-S3).
  2. Server-side encryption doesn't exist for Amazon S3, but only for Amazon EC2.
  3. Server-side encryption allows to upload files using an SSL endpoint for a secure transfer.
  4. Server-side encryption provides an encrypted virtual disk in the cloud.

Answer(s): A

Explanation:

Server-side encryption is about protecting data at rest. Server-side encryption with Amazon S3- managed encryption keys (SSE-S3) employs strong multi-factor encryption. Amazon S3 encrypts each object with a unique key. As an additional safeguard, it encrypts the key itself with a master key that it regularly rotates.


Reference:

http://docs.aws.amazon.com/AmazonS3/latest/dev/UsingServerSideEncryption.html



A user is creating an S3 bucket policy. Which of the below mentioned elements the user will not include as part of it?

  1. Actions
  2. Buckets
  3. Principal
  4. Resource

Answer(s): B

Explanation:

When creating an S3 bucket policy, the user needs to define the resource (which will have the bucket or the object), actions, effect and principal.
They are explained below:
Resources – Buckets and objects are the Amazon S3 resources for which user can allow or deny permissions.
Actions – For each resource, Amazon S3 supports a set of operations. user identifies resource operations which will allow (or deny) by using action keywords
Effect – What the effect will be when the user requests the specific action—this can be either allow or deny.
Principal – The account or user who is allowed access to the actions and resources in the statement. You specify principal only in a bucket policy. It is the user, account, service, or other entity who is the recipient of this permission. In a user policy, the user to which the policy is attached is the implicit principal.


Reference:

http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-languageoverview.html



An IAM user is performing an operation on another account's S3 bucket. What will S3 first check in this context?

  1. Verifies that the bucket has the required policy defined for access the IAM user
  2. Verifies if the parent account of the IAM user has granted sufficient permission
  3. Reject the request since the IAM user does not belong to the root account
  4. Verifies if the IAM policy is available for the root account to provide permission to the other IAM users

Answer(s): B



You can use in an Amazon S3 bucket policy for cross-account access, which means an AWS account can access resources in another AWS account.

  1. access key IDs
  2. secret access keys
  3. account IDs
  4. canonical user IDs

Answer(s): D

Explanation:

You can use canonical user IDs in an Amazon S3 bucket policy for cross-account access, which means an AWS account can access resources in another AWS account. For example, to grant another AWS account access to your bucket, you specify the account's canonical user ID in the bucket's policy.


Reference:

http://docs.aws.amazon.com/general/latest/gr/acct-identifiers.html



A root account owner is trying to understand the S3 bucket ACL. Which choice below is a not a predefined group which can be granted object access via ACL?

  1. Canonical user group
  2. Log Delivery Group
  3. All users group
  4. Authenticated user group

Answer(s): A

Explanation:

An S3 bucket ACL grantee can be an AWS account or one of the predefined Amazon S3 groups. Amazon S3 has a set of predefined groups. When granting account access to a group, the user can specify one of the URLs of that group instead of a canonical user ID. Amazon S3 has the following predefined groups:
. Authenticated Users group: It represents all AWS accounts.
. All Users group: Access permission to this group allows anyone to access the resource.
. Log Delivery group: WRITE permission on a bucket enables this group to write server access logs to the bucket.


Reference:

http://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html



Share your comments for Amazon AWS-Certified-Big-Data-Specialty exam with other users:

E
exampei
10/7/2023 8:14:00 AM

i will wait impatiently. thank youu

P
Prince
10/31/2023 9:09:00 PM

is it possible to clear the exam if we focus on only these 156 questions instead of 623 questions? kindly help!

A
Ali Azam
12/7/2023 1:51:00 AM

really helped with preparation of my scrum exam

J
Jerman
9/29/2023 8:46:00 AM

very informative and through explanations

J
Jimmy
11/4/2023 12:11:00 PM

prep for exam

A
Abhi
9/19/2023 1:22:00 PM

thanks for helping us

M
mrtom33
11/20/2023 4:51:00 AM

i prepared for the eccouncil 350-401 exam. i scored 92% on the test.

J
JUAN
6/28/2023 2:12:00 AM

aba questions to practice

L
LK
1/2/2024 11:56:00 AM

great content

S
Srijeeta
10/8/2023 6:24:00 AM

how do i get the remaining questions?

J
Jovanne
7/26/2022 11:42:00 PM

well formatted pdf and the test engine software is free. well worth the money i sept.

C
CHINIMILLI SATISH
8/29/2023 6:22:00 AM

looking for 1z0-116

P
Pedro Afonso
1/15/2024 8:01:00 AM

in question 22, shouldnt be in the data (option a) layer?

P
Pushkar
11/7/2022 12:12:00 AM

the questions are incredibly close to real exam. you people are amazing.

A
Ankit S
11/13/2023 3:58:00 AM

q15. answer is b. simple

S
S. R
12/8/2023 9:41:00 AM

great practice

M
Mungara
3/14/2023 12:10:00 AM

thanks to this exam dumps, i felt confident and passed my exam with ease.

A
Anonymous
7/25/2023 2:55:00 AM

need 1z0-1105-22 exam

N
Nigora
5/31/2022 10:05:00 PM

this is a beautiful tool. passed after a week of studying.

A
Av dey
8/16/2023 2:35:00 PM

can you please upload the dumps for 1z0-1096-23 for oracle

M
Mayur Shermale
11/23/2023 12:22:00 AM

its intresting, i would like to learn more abouth this

J
JM
12/19/2023 2:23:00 PM

q252: dns poisoning is the correct answer, not locator redirection. beaconing is detected from a host. this indicates that the system has been infected with malware, which could be the source of local dns poisoning. location redirection works by either embedding the redirection in the original websites code or having a user click on a url that has an embedded redirect. since users at a different office are not getting redirected, it isnt an embedded redirection on the original website and since the user is manually typing in the url and not clicking a link, it isnt a modified link.

F
Freddie
12/12/2023 12:37:00 PM

helpful dump questions

D
Da Costa
8/25/2023 7:30:00 AM

question 423 eigrp uses metric

B
Bsmaind
8/20/2023 9:22:00 AM

hello nice dumps

B
beau
1/12/2024 4:53:00 PM

good resource for learning

S
Sandeep
12/29/2023 4:07:00 AM

very useful

K
kevin
9/29/2023 8:04:00 AM

physical tempering techniques

B
Blessious Phiri
8/15/2023 4:08:00 PM

its giving best technical knowledge

T
Testbear
6/13/2023 11:15:00 AM

please upload

S
shime
10/24/2023 4:23:00 AM

great question with explanation thanks!!

T
Thembelani
5/30/2023 2:40:00 AM

does this exam have lab sections?

S
Shin
9/8/2023 5:31:00 AM

please upload

P
priti kagwade
7/22/2023 5:17:00 AM

please upload the braindump for .net

AI Tutor 👋 I’m here to help!