🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 6 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare SaaS provider hosts a static React portal in an Amazon S3 bucket served through Amazon CloudFront. New compliance rules require each external user to authenticate with two distinct factors (knowledge and possession). The DevOps team wants a fully managed, serverless solution that avoids custom authentication code. Which option best meets the requirement?

  • Require CloudFront mutual TLS with ACM-issued client certificates and add the certificates to each user's mobile wallet.

  • Configure an Amazon Cognito user pool, enable TOTP-based MFA, and use the Cognito hosted sign-in UI to protect the CloudFront origin.

  • Enable AWS IAM Identity Center, create users in the directory, and enforce a 15-character password with quarterly rotation.

  • Store salted password hashes in AWS Secrets Manager and invoke them from a Lambda@Edge function on every login request.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot