🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A financial services company runs its workloads in AWS. Regulators require that the private keys used for digitally signing customer loan documents be stored in hardware validated to at least FIPS 140-2 Level 3 and that an approved escrow agent can recover those keys if the institution ceases operations. Which solution best satisfies these requirements while minimizing ongoing operational overhead?

  • Import the private key into AWS Certificate Manager (ACM) as part of a public certificate and grant the escrow agent IAM read access to the certificate.

  • Provision an AWS CloudHSM cluster, generate the signing keys inside the HSMs, and provide an encrypted CloudHSM backup to the designated escrow agent for recovery purposes.

  • Create a customer-managed symmetric CMK in AWS KMS, enable annual automatic rotation, and share the key ARN with the escrow agent.

  • Store the private keys as encrypted plaintext files in Amazon S3, protected by server-side encryption with an AWS-managed KMS key and cross-Region replication.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot