🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company is migrating a medical imaging archive containing protected health information (PHI) to Amazon S3. Compliance rules require strong encryption at rest, but the engineering team also wants to minimize encryption-related CPU overhead and latency for both uploads and downloads. When configuring server-side encryption with AWS Key Management Service (KMS), which cipher and key type will best satisfy these security and performance requirements?

  • ECC-based encryption using a 521-bit public key stored in AWS CloudHSM

  • RSA-2048 asymmetric encryption with customer-provided keys (SSE-C)

  • Triple DES (3DES) with a 168-bit key through client-side encryption libraries

  • AES-256 symmetric encryption managed by AWS KMS (SSE-KMS)

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot