🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your security team needs cryptographic assurance that 100 GB database backup files copied nightly from on-premises storage to an Amazon S3 bucket have not been altered in transit or while stored. They must also be able to programmatically re-verify each object's integrity before a restore operation without decrypting the data. Which approach provides this capability with the least operational overhead?

  • Maintain an external manifest of object names and sizes in the AWS Glue Data Catalog and compare the manifest before every restore.

  • Enable server-side encryption with customer-provided keys (SSE-C) so that S3 validates the MD5 digest of the encryption key during both upload and download operations.

  • Use AWS Backup to copy the S3 bucket to another Region with Object Lock enabled, relying on immutability to guarantee integrity of the backup data.

  • Have the backup workflow calculate a SHA-256 checksum for each file and include it in the x-amz-checksum-sha256 header (or set ChecksumAlgorithm=SHA-256) when uploading, allowing Amazon S3 to verify the checksum on upload, store it as metadata, and return it in response headers for client-side integrity re-checks.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot