🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare organization runs a patient portal on-premises. A third-party telemedicine vendor provides a JavaScript widget that must be embedded in the portal pages to enable video visits. The widget needs to call the vendor's REST API and read basic patient demographics stored in the portal's backend database. Security policy requires zero trust for third-party code, minimal attack surface, and continued compliance with HIPAA. Which strategy BEST satisfies the requirements?

  • Allow the widget to run inside the main portal origin, grant it database read access via shared session cookies, and restrict vendor API calls using CORS rules.

  • Containerize the widget as a microservice in the same Kubernetes pod as the portal backend, share a service account that can query the database, and proxy vendor API traffic through the portal backend.

  • Host the widget in an isolated subdomain, have it call the vendor API directly from the browser, and expose patient data through a new public API secured with OAuth 2.0 access tokens scoped to the required fields only.

  • Deliver the widget through the vendor's CDN, place the entire portal behind the vendor's reverse proxy, and let the vendor issue and validate tokens when the widget needs patient data.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot