SCS-C02 Question 23
Select 4A company is drafting its incident response plan for managing security incidents in its AWS environment. Which of the following roles and responsibilities should be explicitly outlined in the plan to ensure effective incident response?
- A
Appointing a specific team to analyze and contain security incidents
- B
Defining a process for escalating incidents to AWS Support when required
- C
Assigning ownership of implementing IAM policies across AWS accounts
- D
Establishing a communication protocol for notifying stakeholders during incidents
- E
Outlining the responsibility for maintaining compliance logs and evidence
- F
Delegating the responsibility for patching and updating EC2 instances to the incident response team
Show answer and explanation
Correct answers: A, B, D, E
Explanation
Incident response plans must clearly define roles and responsibilities to ensure an organized and effective response to security incidents. This includes having a team for analysis and containment, a process for escalation to AWS Support, a protocol for stakeholder communication, and responsibilities for maintaining compliance evidence. However, tasks like implementing IAM policies and routine patching fall under general security operations and are not typically specific to incident response.
- A. Correct.
Correct. Appointing a dedicated team ensures there is a clear structure for analyzing and containing incidents, which is critical in an AWS incident response plan.
- B. Correct.
Correct. Escalating incidents to AWS Support, when needed, ensures the company can leverage AWS expertise to resolve incidents effectively.
- C. Incorrect.
Incorrect. While IAM policies are important for security, their implementation is generally a broader security operations responsibility, not necessarily tied to incident response roles.
- D. Correct.
Correct. A defined communication protocol ensures stakeholders are informed promptly, minimizing confusion during an incident.
- E. Correct.
Correct. Maintaining compliance logs and evidence is crucial for post-incident analysis and audits, making it a key responsibility in the incident response plan.
- F. Incorrect.
Incorrect. Patching and updating EC2 instances is typically a routine operational task, not directly a responsibility of the incident response team.