🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company is migrating its PCI-DSS cardholder data environment to AWS. Primary Account Numbers (PANs) will be stored in an Amazon RDS for PostgreSQL database. To satisfy PCI-DSS Requirement 3, the PAN must be rendered unreadable at rest and the associated encryption keys must be protected and managed separately from the data. The security team also wants to minimize ongoing operational overhead. Which solution best meets these requirements?

  • Encrypt each PAN in the application with AES-256 using a hard-coded key embedded in the application code and store the ciphertext in the database.

  • Store only the first six and last four digits of each PAN in plaintext; no encryption is required if full PANs are not retained in the table.

  • Create the database with Amazon RDS encryption at rest enabled, using an AWS KMS customer-managed key that is administered by a separate security team.

  • Enable native Transparent Data Encryption (TDE) in Amazon RDS for PostgreSQL and store the TDE master key in an AWS KMS customer-managed key with automatic rotation.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot