🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A healthcare startup stores diagnostic images containing protected health information (PHI) in an Amazon S3 bucket that is accessed by a web application. Compliance staff require the data to remain confidential both in transit and at rest while operations teams want the simplest possible key-management workflow. Which approach best prevents unauthorized disclosure of the images and meets these requirements?

  • Configure server-side encryption with Amazon S3-managed AES-256 keys (SSE-S3) and require all application traffic to the bucket to use HTTPS.

  • Rely solely on private-bucket permissions enforced by AWS Identity and Access Management (IAM).

  • Implement client-side encryption using a customer-managed KMS key and mandate TLS for uploads and downloads.

  • Enable cross-region replication of the bucket to another AWS account to add an extra security layer.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot