🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 7 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company runs multiple AWS accounts under AWS Organizations. The security team aims to remove standing administrator rights yet let on-call engineers get temporary full access during emergencies. Requirements: no long-lived access keys on engineer identities, a 60-minute maximum elevation session, and centralized auditing of every elevation event without additional infrastructure. Which solution best meets these goals?

  • Create an IAM user called EmergencyAdmin in every account, attach AdministratorAccess, and mandate MFA for console sign-in.

  • Store a shared set of Administrator access keys in AWS Secrets Manager; grant engineers read access to the secret only when on call.

  • Enable CloudTrail in all accounts and schedule an AWS Lambda function to attach and remove AdministratorAccess to engineer IAM users on demand.

  • Create an IAM role with AdministratorAccess, set its maximum session duration to 1 hour, require MFA for AssumeRole, and rely on AWS CloudTrail for logging.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot