🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A fintech startup runs its Java microservices in an Auto Scaling group of Amazon EC2 instances across two Availability Zones. The CISO has read about cache-based side-channel techniques that might let a malicious tenant on the same physical server access secrets from the company's virtual machines. Which action best mitigates the risk of this type of inter-VM attack without redesigning the VPC networking or changing application code?

  • Restrict each instance's security group to accept traffic only from the Application Load Balancer and required AWS service endpoints.

  • Place all instances in a spread placement group to force distribution across different racks and minimize correlated failures.

  • Provision the Auto Scaling group to use EC2 Dedicated Hosts so that only your company's instances run on each physical server.

  • Enable VPC Flow Logs and Amazon GuardDuty to detect anomalous east-west traffic between instances.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot