🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare provider is migrating its on-premises patient-record system into AWS. The records will reside in a new Amazon RDS for PostgreSQL instance. Regulations require that all patient data be encrypted at rest with encryption keys rotated annually and centrally managed. The application team cannot modify the workload to handle encryption. Which solution BEST satisfies these security and operational requirements?

  • Run PostgreSQL on Amazon EC2 and use LUKS to encrypt the attached EBS volumes with self-managed keys.

  • Implement field-level client-side encryption in the application using the AWS Encryption SDK and store ciphertext in the database.

  • Rely on default Amazon EBS encryption for the RDS instance's underlying volumes after launch.

  • Enable encryption at rest on the RDS instance using an AWS KMS customer managed key, and turn on key rotation in KMS.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot