🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An e-commerce company stores customers' profile photos and government ID scans in a private Amazon S3 bucket. To comply with data privacy principles of confidentiality and least-privilege access, only a dedicated fraud-analysis application should be able to read the objects, and the security team needs a central record of every object-level access. Which solution best meets these requirements while adding the least operational overhead?

  • Archive the objects to Amazon S3 Glacier Deep Archive with vault lock, grant the fraud-analysis application full S3 access through an IAM user, and rely on CloudWatch metrics to track retrievals.

  • Enable server-side encryption with AWS KMS (SSE-KMS) on the bucket, apply a bucket policy that allows only the fraud-analysis IAM role to perform GetObject, and turn on AWS CloudTrail data events for the bucket to log every object-level access.

  • Migrate the images to an encrypted Amazon EBS volume attached to the fraud-analysis EC2 instance and capture VPC Flow Logs for the subnet to monitor access attempts.

  • Create an S3 VPC gateway endpoint, block public access on the bucket, control traffic with network ACLs, and enable S3 server access logging for auditing.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot