SSCP • Practice Test 26
Free SSCP practice test — 15 questions with explanations. Set 26. No signup required.
A healthcare organization stores patient records in a database that is encrypted at rest using AES-256-CBC. The encryption key is stored in a plaintext configuration file on the database server, with file permissions set to read-only for the database service account and administrators. During an internal audit, the security team flags this as a critical vulnerability because the key is co-located with the encrypted data. The system administrator argues that the file permissions are sufficient to prevent unauthorized access. Separately, the organization must comply with HIPAA requirements for encryption key management. Which remediation most effectively addresses the vulnerability and meets compliance requirements?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.