🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security engineer is tasked with detecting unauthorized changes to critical system binaries on a fleet of Linux-based Amazon EC2 instances that reside in private subnets behind a NAT gateway. The team also wants to limit the amount of additional network traffic that leaves each instance while still receiving near-real-time alerts. Which solution best meets these requirements?

  • Install a host-based intrusion detection agent on each EC2 instance to monitor file integrity and local logs, forwarding only alert metadata to a central SIEM.

  • Deploy a network-based intrusion detection system on a dedicated EC2 instance that inspects mirrored traffic from the private subnets using VPC Traffic Mirroring.

  • Enable VPC Flow Logs for the subnets and rely on Amazon GuardDuty findings to identify unauthorized file modifications.

  • Configure AWS WAF on the Application Load Balancer to block malicious HTTP requests that attempt to modify server files.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot