SCS-C02 Question 24
Single answerYour organization has recently adopted an AWS Incident Response Plan (IRP). During a simulated security incident, it is observed that no one is clearly responsible for determining whether sensitive data was accessed or exfiltrated. Which role in the incident response plan should take responsibility for investigating data access and exfiltration during an incident?
- A
Incident Response Team Lead
- B
Forensic Investigator
- C
AWS Security Hub Administrator
- D
Legal and Compliance Officer
Show answer and explanation
Correct answer: B
Explanation
The Forensic Investigator is the correct role for investigating and analyzing evidence related to an incident, such as determining whether sensitive data was accessed or exfiltrated. This role requires expertise in analyzing logs, network traffic, and other data sources to identify the scope and impact of a security breach. While other roles have important responsibilities in the incident response process, the Forensic Investigator is best suited for this specific task.
- A. Incorrect.
The Incident Response Team Lead is responsible for coordinating and directing the overall response effort but typically does not perform detailed investigative tasks like analyzing data access or exfiltration.
- B. Correct.
The Forensic Investigator is the role responsible for investigating and analyzing evidence related to the incident, including determining whether sensitive data was accessed or exfiltrated.
- C. Incorrect.
The AWS Security Hub Administrator is responsible for managing and configuring AWS Security Hub, which consolidates security alerts, but this role does not specifically focus on investigating data access or exfiltration.
- D. Incorrect.
The Legal and Compliance Officer ensures that the organization complies with legal requirements and regulations during incident response, but they are not responsible for forensic investigations.