SCS-C02 exam dumps

SCS-C02 practice question 5 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 5

Select 2

Your organization has recently experienced a security incident where an Amazon EC2 instance was compromised. To respond effectively, you need to design and implement an incident response plan specific to AWS. Which of the following actions should you include in your plan? (Choose TWO)

  1. A

    Isolate the compromised EC2 instance by modifying the associated security group to deny all inbound and outbound traffic.

  2. B

    Immediately delete the compromised EC2 instance to prevent further exploitation.

  3. C

    Implement Amazon GuardDuty to continuously monitor for suspicious activity and generate alerts.

  4. D

    Conduct a forensic analysis on the compromised EC2 instance by creating an Amazon EBS snapshot and preserving the instance's state.

  5. E

    Disable all IAM user accounts in the AWS account to prevent further unauthorized access.

Show answer and explanation

Correct answers: A, D

Explanation

An effective incident response plan should focus on containing the threat and preserving evidence for investigation. Isolating the compromised EC2 instance prevents further damage and keeps the environment secure, while creating an EBS snapshot ensures that evidence is preserved for forensic analysis. Proactive measures like GuardDuty and extreme actions like disabling all IAM users are not directly relevant to responding to the specific incident.

  • A. Correct.

    Isolating the compromised EC2 instance is a critical step in an incident response plan to prevent further exploitation while preserving the instance for investigation.

  • B. Incorrect.

    Deleting the instance eliminates valuable forensic evidence and hinders the ability to investigate the root cause of the incident.

  • C. Incorrect.

    While Amazon GuardDuty is a valuable monitoring tool, it is a proactive measure rather than a direct step in responding to an already compromised instance.

  • D. Correct.

    Conducting a forensic analysis by creating an EBS snapshot helps preserve evidence and aids in understanding the nature of the compromise.

  • E. Incorrect.

    Disabling all IAM user accounts is an extreme action that disrupts legitimate access and is not necessary in most incident response scenarios; instead, you should focus on reviewing and revoking only suspicious credentials.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam