🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your security team uses the AWS CLI to copy nightly financial reports from an encrypted S3 bucket to an external auditor's on-premises system. Policy requires the reports be encrypted so only the auditor can decrypt them, and your company must never possess the decryption key. Which approach meets these requirements with minimal changes to the current workflow?

  • Encrypt each report on the client with the auditor's RSA public key before uploading to S3; the auditor decrypts the files with the corresponding private key.

  • Create an asymmetric CMK in AWS KMS, export its private key to the auditor, and use the CMK's public key for client-side encryption.

  • Enable default encryption on the S3 bucket using SSE-S3 so Amazon S3 encrypts all objects before transfer.

  • Configure S3 server-side encryption with a customer-managed symmetric CMK in AWS KMS and share the CMK with the auditor.

ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot