🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company operates several AWS accounts under AWS Organizations. The security policy states that every create, modify, or delete API call must be traceable to the exact IAM user or role that issued it, even if malicious admins try to erase local evidence. Which solution BEST enforces this accountability requirement?

  • Enable AWS Config in every member account and aggregate configuration snapshots into a central repository for the security team.

  • Schedule AWS Trusted Advisor to run weekly in each account and export the reports to the security team's account.

  • Create an organization-wide CloudTrail and store its logs in an S3 bucket owned by a dedicated security account with log file integrity validation enabled.

  • Turn on detailed CloudWatch monitoring for all services and forward the metrics to a centralized monitoring account.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot