🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare startup is launching a patient portal on AWS. Patient registration records with names, birth dates, and Social Security numbers will be stored in an Amazon RDS for PostgreSQL DB. Regulations require the PII be encrypted at rest, encryption keys rotate automatically each year, and no application code changes are allowed. Which solution meets all requirements while keeping operational overhead low?

  • Require SSL/TLS for all application connections to RDS and restrict public network access to the database subnet.

  • Attach encrypted Amazon EBS volumes to application servers and enable operating-system full-disk encryption instead of encrypting RDS.

  • Enable Amazon RDS encryption at rest with an AWS KMS customer master key (CMK) and configure automatic annual key rotation.

  • Implement client-side field-level encryption of PII with RSA-2048 in the application and store the ciphertext in RDS.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot