🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company processes EU residents' personal data in AWS. Compliance requires that no related AWS resources be created outside the European Economic Area. Development teams operate in multiple AWS Organizations member accounts and must keep the ability to create resources on demand. Which approach best enforces this residency requirement across all accounts while still letting teams self-provision in approved EU regions?

  • Deploy AWS Config rules to detect resources outside approved Regions and invoke a Lambda function that deletes them immediately after creation.

  • Require developers to tag all resources with Region=EU and use an IAM permissions boundary that allows operations only when the aws:TagKeys condition includes that value.

  • Enable AWS CloudTrail in all accounts and create an Amazon EventBridge rule that triggers an alert whenever a resource is launched in a non-EU Region.

  • Attach a Service Control Policy to the AWS Organizations root that denies any Create*, Run*, or Put* API calls when aws:RequestedRegion is not one of eu-central-1, eu-west-1, or eu-north-1.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot