🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare startup hosts a web application on AWS that lets patients upload medical records to an Amazon S3 bucket. To satisfy HIPAA's mandate to prevent unauthorized disclosure of Protected Health Information (PHI) and to detect any later tampering with stored objects, the team wants a solution that requires minimal ongoing key or infrastructure management. Which approach best meets these requirements?

  • Use client-side RSA encryption for every file and rely on the ETag value returned by S3 uploads as proof of file integrity.

  • Encrypt each file locally with AES-256 using a shared secret key and upload it to an S3 bucket that has a public-read ACL to simplify access controls.

  • Enable S3 Server-Side Encryption with AWS KMS (SSE-KMS) and require each upload to include an SHA-256 checksum stored in object metadata for later verification.

  • Store the files unencrypted in S3 but enable bucket versioning and AWS CloudTrail data events to detect any unwanted changes.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot