easyMultiple ChoiceObjective-mapped
SSCP Practice Question: Is migrating its on-premises applications to a…
An organization is migrating its on-premises applications to a cloud provider. Which of the following security controls should be implemented to protect data at rest in the cloud?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable server-side encryption on storage services.
Enable server-side encryption on storage services. Server-side encryption ensures data is encrypted at rest by the cloud provider, protecting it from unauthorized access even if storage media is compromised. Option A (multi-factor authentication) protects access but not data at rest. Option B (network segmentation) primarily protects data in transit and network boundaries. Option C (access keys for API authentication) is for identity and access management, not data encryption. Option D (CloudTrail or equivalent audit logging) provides detective controls, not data protection at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement multi-factor authentication for all users.
Why it's wrong here
MFA protects user accounts, not data at rest.
- ✗
Configure network segmentation using VPCs.
Why it's wrong here
Network segmentation controls traffic flow, not data at rest.
- ✗
Use access keys for API authentication.
Why it's wrong here
Access keys control programmatic access, not encryption.
- ✗
Enable CloudTrail or equivalent audit logging.
Why it's wrong here
Audit logs track activities, do not protect data at rest.
- ✓
Enable server-side encryption on storage services.
Why this is correct
Server-side encryption encrypts data at rest automatically.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.