🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 5 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization is migrating an on-premises HR application that stores sensitive employee PII to Amazon S3. To meet PCI-DSS requirements, the data must be encrypted at rest, encryption keys must be managed separately from the data, and operations staff want to avoid running their own key infrastructure. Which approach best satisfies these confidentiality requirements while minimizing operational overhead?

  • Configure server-side encryption with AWS Key Management Service keys (SSE-KMS) and attach a bucket policy that requires all uploads to specify the KMS key.

  • Require client-side encryption using customer-provided keys stored in an on-premises hardware security module (HSM) before uploading each object to S3.

  • Migrate the data to encrypted Amazon EBS volumes attached to an EC2 instance and expose the files through an SFTP server.

  • Enable server-side encryption with Amazon S3 managed keys (SSE-S3) on the bucket that stores the HR data.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot