SCS-C02 exam dumps

SCS-C02 practice question 7 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 7

Select 3

Your organization has recently adopted AWS and is designing an incident response plan to handle potential security breaches. As part of the plan, the organization wants to ensure that compromised resources are isolated automatically to prevent further damage. Which of the following actions should be included in the plan to achieve this goal?

  1. A

    Set up AWS Config rules to detect non-compliant resources and trigger AWS Lambda functions to isolate them.

  2. B

    Use AWS Systems Manager Automation documents (SSM Documents) to terminate compromised EC2 instances.

  3. C

    Create Amazon GuardDuty findings to automatically isolate the resource by moving it to a quarantine VPC using AWS Lambda.

  4. D

    Enable Detective to automatically isolate resources identified as part of a security anomaly.

  5. E

    Integrate AWS Security Hub with automation rules to isolate non-compliant resources using AWS Config and Lambda.

Show answer and explanation

Correct answers: A, C, E

Explanation

To design an effective incident response plan in AWS, it is essential to automate the isolation of compromised resources to prevent further damage. Using AWS Config rules and Lambda or GuardDuty findings with Lambda, resources can be moved to a quarantine VPC. Additionally, AWS Security Hub can orchestrate automated actions by integrating with AWS Config and Lambda to ensure non-compliant resources are isolated effectively. These approaches align with AWS best practices for incident response.

  • A. Correct.

    Correct: AWS Config rules can monitor resource compliance, and when a resource is deemed non-compliant (e.g., compromised), a Lambda function can be triggered to isolate it.

  • B. Incorrect.

    Incorrect: AWS Systems Manager Automation documents can perform various actions, but terminating an instance directly doesn't isolate it. Isolation typically involves network or resource containment rather than deletion.

  • C. Correct.

    Correct: GuardDuty findings can trigger AWS Lambda functions to move compromised resources to a quarantine VPC, effectively isolating them.

  • D. Incorrect.

    Incorrect: AWS Detective is a service for investigation and analysis of security incidents; it does not have built-in functionality for isolating resources.

  • E. Correct.

    Correct: AWS Security Hub integrates with automation tools like AWS Config and Lambda, enabling the isolation of non-compliant resources as part of a security response.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam