🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 6 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your organization runs workloads in AWS and uses Microsoft Entra ID (Azure AD) as its corporate IdP integrated with AWS IAM Identity Center for federated logins. HR maintains Workday as system of record. Security operations wants to reduce onboarding errors and ensure new hires receive only job-appropriate AWS permissions on their first day without manual intervention. Which strategy BEST fulfills SSCP provisioning best practices?

  • Configure Workday to emit SCIM events to Azure AD, map users to security groups representing job roles, and let IAM Identity Center automatically provision corresponding permission sets in AWS.

  • Create a Python script that daily pulls a CSV from HR and uses AWS CLI to attach the AdministratorAccess policy to each new user created in AWS IAM.

  • Enable AWS root account credentials for every new hire and enforce password rotation every 90 days through an internal policy.

  • Require team leads to submit IAM user creation requests via email to the cloud team, which manually provisions users using the console and applies policies as requested.

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot