🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An organization stores compliance reports in an encrypted Amazon S3 bucket. External auditors must have read-only access for the next two weeks. The security team must follow least-privilege principles, avoid creating long-lived IAM users, and ensure that access can be revoked immediately if the engagement ends early. Which approach best meets these requirements?

  • Add a bucket ACL that grants READ permission to the auditors' corporate email addresses.

  • Create an IAM role that allows only s3:GetObject on the bucket and let the auditors assume the role using temporary security credentials for the two-week period.

  • Attach a bucket policy that allows any principal to GetObject when the request originates from the auditors' office IP addresses.

  • Provision an IAM user for each auditor, attach the AmazonS3ReadOnlyAccess managed policy, and set a 14-day password expiration.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot