🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company ingests 5 GB of sensitive customer telemetry each hour from on-premises servers to an Amazon S3 data lake. Analysis jobs on multiple Amazon EC2 instances must later download and decrypt the objects. Management requires strong confidentiality while minimizing CPU overhead during both upload and processing. Which approach best satisfies these requirements?

  • Hash each file with SHA-256 and upload both the hash and the plaintext file to S3 for later integrity checks.

  • Attach an ECDSA digital signature to every file and store the file unencrypted in S3, relying on the signature for protection.

  • Call AWS KMS GenerateDataKey for each upload, encrypt the file client-side with AES-256-GCM, and store the KMS-encrypted data key with the object so authorized EC2 instances can decrypt and use it.

  • Encrypt each file with a unique RSA-4096 public key for every EC2 instance before uploading to S3.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot