🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security engineer must allow employees authenticated in the company's on-premises Active Directory (AD) forest to seamlessly sign in to Windows instances that are joined to an AWS Managed Microsoft AD directory. Management stipulates that only corporate identities should reach AWS resources and that no identities or services hosted in AWS may access on-premises network resources through the trust. Given these requirements, which trust configuration should the engineer implement between the two forests?

  • Establish a two-way, transitive forest trust between AWS Managed Microsoft AD and the on-premises AD forest.

  • Create a one-way, non-transitive outgoing forest trust from AWS Managed Microsoft AD to the on-premises AD forest.

  • Configure a one-way, non-transitive incoming forest trust on AWS Managed Microsoft AD so that the on-premises AD forest is the trusting domain.

  • Deploy a shortcut trust to enable direct Kerberos referrals between the two forests in both directions.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot