🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security engineer encrypts 500-MB log archives before uploading them to Amazon S3. The current workflow uses RSA with 2048-bit keys to encrypt each file directly, resulting in multi-minute processing times and high CPU utilization. Management now demands equal or stronger confidentiality while reducing both encryption/decryption time and storage overhead. Which approach best satisfies these requirements?

  • Adopt AES-128 in ECB mode to benefit from faster symmetric encryption while maintaining adequate strength.

  • Use AES-256 in GCM mode to encrypt each file with a random 256-bit data key and protect that key using AWS KMS.

  • Increase the RSA key size to 4096 bits and continue encrypting each file directly with the larger key.

  • Switch to 3DES in CBC mode with a 168-bit key because the shorter key reduces CPU cycles.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot