🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company hosts a payment-processing web application behind an AWS Application Load Balancer (ALB). A recent penetration test shows the site is vulnerable to the POODLE attack because the listener's security policy still allows SSLv3 and TLS 1.0. Legacy business partners insist on broad browser compatibility, but the security team must eliminate exposure while keeping the site available. Which action best meets security requirements with minimal operational impact?

  • Attach an AWS WAF rule that blocks ClientHello messages containing the SSLv3 version number while leaving the existing listener policy unchanged.

  • Update the ALB to use an AWS predefined security policy that disables SSLv3 and TLS 1.0/1.1 and permits only TLS 1.2 or later with strong ciphers.

  • Enable mutual TLS on the ALB so that only clients presenting a trusted certificate can complete the handshake over SSLv3 or TLS 1.0.

  • Move TLS termination from the ALB to each EC2 instance and rely on the instances' operating systems to negotiate secure protocols.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot