🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your security team runs an AWS CloudHSM cluster that protects the private root-CA key used by an internal public key infrastructure (PKI). A new regulatory control now mandates split knowledge for any future key recovery or export operation, while allowing the existing automated online signing process to continue unaffected. Which change to the CloudHSM configuration BEST meets this requirement?

  • Modify the signing application to prompt for two separate Crypto User credentials before every signing transaction.

  • Rotate the cluster's security group keys and enable automatic HSM node scaling across Availability Zones.

  • Export the private key to a software keystore protected by a server-based TPM and disable key export on the HSM thereafter.

  • Enable M-of-N authorization for the Crypto Officer role so that a quorum of operators must authenticate before any key export or recovery command is accepted.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot