🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 4 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security analyst investigating a potential privilege-escalation incident discovers that an IAM role was modified to attach the AdministratorAccess policy. The incident-response playbook requires collecting a log that shows the exact API call, the calling principal, source IP address, and timestamp before escalating the case to the CSIRT. Which AWS data source will most reliably provide all of this information?

  • Amazon CloudWatch metrics collected for IAM service events

  • AWS Config configuration snapshots

  • VPC Flow Logs for the role's attached network interfaces

  • AWS CloudTrail management event logs

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot