Courseiva
easyMultiple ChoiceObjective-mapped

SSCP Practice Question: Is migrating its on-premises applications to a…

An organization is migrating its on-premises applications to a cloud provider. Which of the following security controls should be implemented to protect data at rest in the cloud?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable server-side encryption on storage services.

Enable server-side encryption on storage services. Server-side encryption ensures data is encrypted at rest by the cloud provider, protecting it from unauthorized access even if storage media is compromised. Option A (multi-factor authentication) protects access but not data at rest. Option B (network segmentation) primarily protects data in transit and network boundaries. Option C (access keys for API authentication) is for identity and access management, not data encryption. Option D (CloudTrail or equivalent audit logging) provides detective controls, not data protection at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement multi-factor authentication for all users.

    Why it's wrong here

    MFA protects user accounts, not data at rest.

  • Configure network segmentation using VPCs.

    Why it's wrong here

    Network segmentation controls traffic flow, not data at rest.

  • Use access keys for API authentication.

    Why it's wrong here

    Access keys control programmatic access, not encryption.

  • Enable CloudTrail or equivalent audit logging.

    Why it's wrong here

    Audit logs track activities, do not protect data at rest.

  • Enable server-side encryption on storage services.

    Why this is correct

    Server-side encryption encrypts data at rest automatically.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.