ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company needs to automate nightly transfers of payroll files that contain PII from an on-premises Linux server to Amazon S3. The security team requires encryption in transit, mutual authentication, and the smallest possible number of inbound firewall openings. Which solution best meets these requirements while aligning with AWS best practices?
Establish an AWS Site-to-Site VPN and continue using plain FTP on port 21 through the tunnel.
Generate presigned Amazon S3 URLs and have the on-premises server upload the files over HTTPS.
Enable FTPS on an AWS Transfer Family endpoint and use X.509 certificates for client authentication.
Create an AWS Transfer Family server that uses the SFTP protocol and authenticate the on-premises host with SSH key pairs, allowing only TCP port 22 through the firewall.
AWS Transfer Family with the SFTP protocol provides end-to-end encryption through the SSH tunnel on a single TCP port (22) and supports key-based client authentication, satisfying the mutual-authentication requirement. FTP inside a Site-to-Site VPN encrypts traffic but still needs UDP 500 and 4500 plus the FTP control/data ports, so more firewall rules are necessary. FTPS on Transfer Family encrypts data, yet it requires port 990 and a range of passive ports, increasing the attack surface. Presigned S3 URLs use HTTPS for encryption but authenticate only the server side, not the client, so mutual authentication is not achieved.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS Transfer Family?
Open an interactive chat with Bash
What is mutual authentication in SFTP?
Open an interactive chat with Bash
Why is port 22 considered secure for SFTP?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .