🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your DevOps team stores startup scripts in an Amazon S3 bucket and distributes them to hundreds of new EC2 instances at launch. To guarantee the scripts are genuine without deploying a full certificate authority, the team uses GNU Privacy Guard (GPG) and a Web-of-Trust model. A new engineer has just published her GPG public key. Which action must each EC2 instance (or its configuration management process) perform so the instances can verify the engineer's future script signatures under the existing trust model?

  • Request a commercially issued X.509 certificate for the engineer's key and distribute the certificate chain to all EC2 instances.

  • Upload the engineer's public key to AWS Certificate Manager and reference it in the S3 bucket policy so instances inherit trust automatically.

  • Import the engineer's public key to each instance and sign it with an already-trusted operations key to extend trust through the Web-of-Trust.

  • Store the engineer's private key in AWS Secrets Manager and allow EC2 instances to retrieve it through an IAM role at launch.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot