🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company operates 150 Amazon EC2 instances spread across several AWS accounts that are all part of one AWS Organization. Policy mandates that every new instance must be discovered automatically and scanned for operating-system and application vulnerabilities within 24 hours, and that all findings be consolidated in a central security account with as little manual effort as possible. Which solution BEST satisfies these requirements while maintaining an accurate asset inventory?

  • Enable Amazon Inspector across the AWS Organization, designate the security account as the delegated administrator, and rely on its continuous EC2 scanning and inventory integration.

  • Create AWS Config rules that check each instance for required tags and IAM role compliance, then export rule evaluation reports to the security account.

  • Activate AWS GuardDuty in every account and forward all threat detection findings to the security account for centralized review.

  • Install a third-party vulnerability scanner on each instance via user data, schedule weekly cron jobs, and email the CSV results to the security team.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot