ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An application running on Amazon EC2 continuously compresses and writes gigabyte-scale log files to local storage before uploading them to encrypted Amazon S3. The security team wants confidentiality for the on-disk logs, minimal CPU overhead during writes, and simple key rotation using AWS KMS. Which approach best meets these requirements?
Encrypt each log file with RSA-2048 using an AWS KMS customer master key (CMK).
Generate a SHA-256 digest of each file and store the hash alongside the file for later verification.
Digitally sign each file with the Elliptic Curve Digital Signature Algorithm (ECDSA) before saving it.
Encrypt each log file locally with AES-256 in Galois/Counter Mode using a data key supplied by AWS KMS.
AES is a symmetric (single-key) block-cipher that is highly efficient in both hardware and software. Using a KMS-generated data key to perform local AES-256 encryption in Galois/Counter Mode (GCM) provides strong confidentiality with integrated integrity protection and enables straightforward key rotation through KMS. RSA and ECDSA are asymmetric operations that are far slower and less suited for bulk data encryption, while SHA-256 produces only a hash and offers no confidentiality.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AES-256 in Galois/Counter Mode (GCM)?
Open an interactive chat with Bash
What is AWS KMS and how does it enable key rotation?
Open an interactive chat with Bash
Why are symmetric encryption algorithms like AES-256 preferred for large-scale data encryption?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .