🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An e-commerce company ingests VPC Flow Logs, AWS CloudTrail events, and application server logs into a dedicated Amazon S3 bucket. An internal audit states that the security team must be able to demonstrate that no one, including administrators, can modify or delete log files for one year and must be able to detect any attempted tampering. The team wants a native, low-maintenance AWS solution. Which action will meet these requirements?

  • Stream all logs to Amazon CloudWatch Logs and set the retention period to Never Expire.

  • Turn on S3 Object Lock in Compliance mode for the log bucket and enable CloudTrail log file integrity validation.

  • Enable bucket versioning and configure cross-region replication to a secondary S3 bucket.

  • Encrypt the log bucket with server-side encryption using an AWS KMS customer-managed key that is rotated annually.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot