SCS-C02 exam dumps

SCS-C02 practice question 64 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 64

Select 3

Your company has detected suspicious activity in an Amazon EC2 instance and suspects it may be compromised. As part of your incident response plan, what steps should you take to isolate the instance and preserve evidence for further investigation?

  1. A

    Detach the instance from its current security groups and attach it to a security group with restrictive rules.

  2. B

    Take a snapshot of the instance’s attached volumes for forensic analysis.

  3. C

    Terminate the compromised instance to prevent further damage to your environment.

  4. D

    Enable VPC Flow Logs for the VPC associated with the instance to capture network traffic details.

  5. E

    Create an IAM role for the instance to allow forensic data collection.

Show answer and explanation

Correct answers: A, B, D

Explanation

During a security incident, isolating the compromised instance and ensuring evidence preservation are critical steps in the incident response process. Detaching the instance from its current security groups, taking snapshots of attached volumes, and enabling VPC Flow Logs ensure that the incident is contained, evidence is preserved, and network activity can be reviewed. Terminating the instance destroys critical evidence, and creating an IAM role after the compromise does not align with best practices for incident response.

  • A. Correct.

    Correct. Detaching the instance from its current security groups and attaching it to a security group with restrictive rules effectively isolates the instance from other network resources, minimizing the risk of further compromise.

  • B. Correct.

    Correct. Taking a snapshot of the attached volumes allows you to preserve evidence for forensic analysis without modifying the original data.

  • C. Incorrect.

    Incorrect. Terminating the instance would destroy evidence critical to the investigation and is not aligned with best practices for incident response.

  • D. Correct.

    Correct. Enabling VPC Flow Logs for the associated VPC captures network activity details, which are valuable for understanding the scope of the incident and identifying malicious activity.

  • E. Incorrect.

    Incorrect. While an IAM role can be used to grant permissions, creating one for the instance after the compromise does not directly contribute to isolating the instance or preserving evidence.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam