🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A financial services firm is exposing an internal payment-processing REST API to an external billing partner. The partner's workloads run in several public cloud regions, so their source IP addresses can change without notice. Corporate policy requires least privilege, minimal credential exposure, and the ability to revoke the partner's access quickly if a breach is suspected. Which approach BEST satisfies these requirements?

  • Permit anonymous calls to the API but enforce strict custom rate limiting on sensitive endpoints.

  • Use OAuth 2.0 with an authorization server to issue scoped, short-lived bearer tokens and enforce TLS for every API call.

  • Create a site-to-site IPsec VPN and restrict traffic to the partner's public IP address ranges.

  • Provide the partner a long-lived shared API key that is embedded in their application code.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot