🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

After a developer surrendered AWS access keys during a spear-phishing attack, management asks for an additional administrative control that will lower the chance of similar incidents without affecting system performance or adding significant cost. The control must also generate auditable evidence of employee participation. Which action BEST meets these requirements?

  • Launch mandatory, role-based security awareness training covering phishing and AWS credential handling, and record completion in the corporate learning-management system.

  • Deploy an AWS Config rule that flags any repository commit containing hard-coded access keys for remediation.

  • Enable AWS CloudTrail for all accounts and archive the logs to an immutable S3 bucket in Glacier Deep Archive.

  • Require multi-factor authentication for all IAM users by attaching a policy that denies API calls without MFA.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot