🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security administrator must be alerted within minutes whenever the IAM role named "AppServerRole" is deleted or its attached policies are changed. The solution must keep a history of all configuration states for audits and should avoid writing and maintaining custom code. Which solution best meets these requirements?

  • Enable AWS Config for IAM resources, create a rule that evaluates AppServerRole on every configuration change, and configure the rule to send an Amazon SNS notification when the role is non-compliant.

  • Enable AWS CloudTrail and schedule a daily Amazon Athena query that searches for DeleteRole or PutRolePolicy events, then emails the results through Amazon SES.

  • Run IAM Access Analyzer continuously and configure it to notify the security team of any findings related to AppServerRole.

  • Rely on AWS Trusted Advisor's IAM checks and subscribe the security team to its weekly report of security recommendations.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot