ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a quarterly security review, a security administrator must update the organization's control register to show how each cloud control supports deterrent, preventive, detective, corrective, or compensating functions. For detecting and recording unauthorized changes to the configuration of Amazon EC2 security groups and IAM policies, which AWS service should be documented as the primary detective control?
Detective controls identify events after they have occurred and generate records that can be analyzed or trigger alerts. AWS Config continuously records the configuration state of supported AWS resources, retains a history of changes, and can notify teams when resource settings drift from an approved baseline. This makes it a detective control for unauthorized configuration changes. AWS WAF, AWS Shield Advanced, and AWS Key Management Service are mainly preventive or deterrent controls: they block or mitigate attacks or enforce encryption but do not primarily provide change detection or historical configuration tracking.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does AWS Config do?
Open an interactive chat with Bash
What is the difference between detective and preventive controls?
Open an interactive chat with Bash
How does AWS Config compare to other detective controls?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .