🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your team is building a cross-account AWS solution that stores transcoded media files in Amazon S3. Each object is automatically tagged with a data classification value of Public, Confidential, or Secret. Corporate security policy requires that the classification label alone must dictate which IAM principals can read or overwrite the files, and individual bucket owners must be unable to loosen these restrictions. Which access-control approach best satisfies this requirement?

  • Rely on discretionary access control so each bucket owner can manage access control lists (ACLs) for their objects

  • Use attribute-based access control (ABAC) policies that evaluate the object's classification tag during each access request

  • Implement a mandatory access control model that uses the object's classification label and the subject's clearance, enforced centrally

  • Apply role-based access control by mapping IAM roles to S3 bucket policies for each classification level

ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot