🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An online payment processor runs a serverless data analytics pipeline on AWS. Developers commit code to AWS CodeCommit, and AWS CodePipeline builds and deploys the artifacts to production. To limit insider fraud, the CISO mandates that no single engineer must be able to both modify source code and promote it to production. Which approach best enforces segregation of duties in this environment?

  • Create separate IAM roles so developers can only commit to CodeCommit, require an MFA-protected operations role to approve a manual approval stage in CodePipeline before production deployment, and log all actions with CloudTrail.

  • Enable AWS Config rules and GuardDuty to detect and automatically roll back unauthorized Lambda function changes after deployment.

  • Grant developers permissions to push to CodeCommit and also to release changes through CodePipeline once a peer code review is completed.

  • Use a single DevOps IAM role that combines development and deployment permissions but rely on CloudTrail and GuardDuty for post-deployment investigation.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot