🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A fintech company based in Frankfurt is migrating its web application to AWS. Regulations mandate that all production data and compute resources stay in Germany; any copy outside eu-central-1 is non-compliant. The team will run EC2 instances behind an Application Load Balancer and store user uploads in Amazon S3. Which solution best enforces this jurisdictional requirement while letting the application operate normally?

  • Create an AWS WAF geographic match rule that only allows web requests originating from German IP address ranges.

  • Enable Amazon S3 Cross-Region Replication to eu-west-1 with Replication Time Control so that all object copies are closely synchronized.

  • Encrypt the S3 bucket with a customer-managed AWS KMS key stored in eu-central-1 to prevent decryption outside Germany.

  • Attach an AWS Organizations service control policy that denies all EC2 and S3 API calls when the aws:RequestedRegion is not "eu-central-1".

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot