🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your e-commerce workload runs on multiple Amazon EC2 instances behind an Application Load Balancer. The security team must add a detective control that continuously records any configuration change to the instances or their security groups, compares each change against approved baselines, and sends an immediate alert when non-compliance is detected. Which AWS solution best satisfies these requirements?

  • Use IAM Access Analyzer to continuously scan security group updates and publish findings to Amazon CloudWatch Events.

  • Enable AWS Config recording for all resources, add compliance rules for EC2 instances and security groups, and send rule violation notifications through Amazon SNS.

  • Activate AWS Shield Advanced with proactive event monitoring to generate alerts whenever the environment configuration changes.

  • Attach an AWS WAF web ACL to the Application Load Balancer and use its logging feature to detect unauthorized resource modifications.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot