🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An online insurance startup stores policyholder passport images in an Amazon S3 bucket. Regulations require that all PII be encrypted at rest with customer-controlled keys whose use can be audited, and that every upload or download occurs over encrypted channels. Operations prefers the lowest-maintenance AWS-managed approach. Which solution best meets these compliance and operational requirements?

  • Move the images to an encrypted EBS volume attached to an EC2 SFTP server secured with SSH for uploads.

  • Implement client-side encryption in the application, store the key in application code, and use service control policies to block non-HTTPS traffic.

  • Enable S3 server-side encryption with Amazon-managed keys (SSE-S3) and require HTTPS for all PUT and GET operations.

  • Configure S3 default encryption with AWS KMS using a customer-managed CMK and enforce HTTPS-only access with a bucket policy.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot