🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company operates several production VPCs in separate AWS accounts. During a recent tabletop exercise, incident responders spent 45 minutes downloading forensic utilities and launching temporary analysis hosts before they could begin evidence collection. To strengthen tool and resource readiness, which proactive measure would most effectively eliminate this delay while following AWS security best practices?

  • Require every application team to embed the full forensic toolset in the production AMIs for their workloads.

  • Rely on AWS Marketplace forensic appliance listings and spin them up only after an incident is confirmed.

  • Place installation packages for forensic utilities in an S3 bucket with public read access so responders can download them to any host when needed.

  • Maintain a hardened AMI containing all required forensic tools in a dedicated security tooling account and allow incident responders to launch instances from it using pre-approved IAM roles.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot