Incident Response

Domain 2: Incident Response

27 practice questions for Domain 2 of the AWS Certified Security - Specialty (SCS-C03) exam, which makes up 14% of its scored content. Your answers count towards one score and one timer for the whole exam.

Domain 2: Incident Response

14% of scored content · 27 practice questions

40. An organization must guarantee that incident responders can reach every member account even if a local administrator revokes their permissions. Which solution meets these requirements?

Answer and explanation

Answer: B. A StackSets-deployed role reaches every account including new ones, and a service control policy denying changes to it means a local administrator cannot remove the responders' path in. Long-lived keys can be deleted by that same administrator. Root credentials are unauditable and violate every credential guideline. A written procedure is not an enforced control.

41. An incident response plan must be validated by deliberately impairing a component while a guardrail halts the test if the blast radius grows. Which solution meets these requirements?

Answer and explanation

Answer: A. Fault Injection Service runs defined experiments with stop conditions that halt automatically when a guardrail alarm fires. Manual termination has no guardrail and is not repeatable. A restore test measures recovery time without exercising the response plan. A tabletop review validates understanding rather than system behaviour.

42. A response plan must confirm that a standby environment in a second Region is ready to take traffic before an incident requires it. Which solution meets these requirements?

Answer and explanation

Answer: B. Application Recovery Controller continuously verifies readiness, including capacity and quota, and provides routing controls to shift traffic. Backup copies recovery points without confirming the standby can serve. A canary tests an endpoint without confirming readiness for full load. Config confirms resources exist rather than that they are ready.

43. A forensic analysis capability must be prepared in advance so that evidence from a compromised instance can be examined without risking production. Which solution meets these requirements?

Answer and explanation

Answer: C. Working from a copy in an isolated environment attached read-only prevents malicious content executing against production or altering the evidence. Attaching the original volume to a workstation risks infection and contaminates the chain of custody. Restoring from an AMI destroys the evidence. Publishing snapshots discloses potentially sensitive data.

44. An Amazon EC2 instance is confirmed compromised and must be contained while volatile and persistent evidence is preserved. (Place the steps in the correct order.)

Answer and explanation

Answer: C → D → A → B. Isolation comes first because it stops further communication without destroying state. Memory must be captured before any power event, since volatile evidence is lost the moment the instance stops or reboots. Disk snapshots preserve persistent artifacts and can be taken after the memory image. Detaching from the Auto Scaling group last prevents the group terminating the instance mid-investigation, and doing it earlier would not have protected the volatile evidence. AWS awards no partial credit on an ordering question, so a memory capture placed after the snapshots scores zero.

45. An IAM access key has been published in a public code repository. Which action should be taken first?

Answer and explanation

Answer: C. Deactivating stops further use immediately while preserving the identity and its history for investigation. Rotating leaves the exposed key valid until every consumer is updated. Deleting the user destroys context needed to scope the incident. A blanket account-wide deny causes an outage far beyond the compromised key.

46. After a suspected compromise, all temporary sessions issued by an IAM role must be invalidated while the role remains usable for new sessions. Which solution meets these requirements?

Answer and explanation

Answer: A. A deny conditioned on aws:TokenIssueTime revokes every session issued before the specified instant while permitting new ones, which is the documented revocation procedure. Deleting and recreating breaks dependent configurations. Detaching policies disables the role for legitimate use. Root access keys are unrelated and should not exist.

47. An AWS KMS key is suspected of being used by an unauthorized principal, and existing data encrypted under it must remain decryptable by legitimate users. Which action should be taken?

Answer and explanation

Answer: B. Editing the key policy and revoking grants removes the unauthorized access immediately while legitimate principals continue to decrypt. Scheduling deletion eventually renders all data encrypted under the key unrecoverable. Disabling blocks every principal including legitimate ones. Rotation creates new material but prior access paths remain until the policy changes.

48. A containment action must isolate an instance within two minutes of a specific Amazon GuardDuty finding, without human involvement. Which solution meets these requirements?

Answer and explanation

Answer: D. GuardDuty publishes findings to EventBridge in near real time, and a rule matching the finding type invokes a runbook that performs containment within seconds. An hourly query is far too slow. An SNS notification requires a person to act. A Security Hub insight is a saved view rather than an automated response.

49. Following a data exposure, the team must determine every principal that accessed a specific Amazon S3 object over the past six months. Which source provides this, assuming it was configured in advance?

Answer and explanation

Answer: C. Object-level reads are data events, which record the calling identity and must be enabled beforehand and retained beyond the 90-day event history to cover six months. Management events do not capture object-level access. GuardDuty reports suspicious activity rather than a complete access record. Config tracks bucket configuration rather than object access.

50. An incident response plan must define when an incident is escalated to executive leadership. Which approach is appropriate?

Answer and explanation

Answer: A. Pre-agreed criteria remove judgement from the moment of highest pressure and make escalation consistent. Escalating everything produces noise that trains leadership to ignore it. Ad hoc decisions vary by responder. Escalating after containment deprives leadership of decisions only they can make.

51. A forensic account must be prepared so evidence can be analysed in isolation. Which combination of steps meets these requirements? (Select TWO.)

Answer and explanation

Answer: B, E. Isolation requires no trust or network path from production, and pre-authorising the transfer path means evidence can be moved without configuration changes during an incident. Production administrator access and a network connection both defeat the isolation. Disabling logging removes the record of what investigators did.

52. An incident response plan must be validated against a scenario that cannot be safely executed in production. Which approach is appropriate?

Answer and explanation

Answer: A. A tabletop exercise validates decision-making and communication where live execution is unsafe, while safe scenarios are exercised for real. Skipping validation leaves the plan untested. Executing an unsafe scenario in production causes the incident it simulates. Review by an engineer checks the document rather than the response.

53. An instance must be isolated during an incident, but terminating its network connections would destroy evidence held in active sessions. Which approach is appropriate?

Answer and explanation

Answer: A. An isolation security group prevents new communication while the instance keeps running so volatile state can be captured. Detaching the interface and stopping the instance both disrupt the running state. Terminating destroys it entirely.

54. An IAM role's credentials are suspected compromised, and revoking sessions must not disrupt the legitimate workload using that role. Which approach is appropriate?

Answer and explanation

Answer: B. A token issue time condition revokes sessions issued before the specified instant while allowing the workload to obtain new ones. Detaching policies disables legitimate use. Deleting and recreating breaks trust relationships and dependent configurations. Roles do not hold access keys to rotate.

55. An S3 bucket was made public by a configuration change, and the team must establish what was accessed while it was exposed. Which source provides this?

Answer and explanation

Answer: A. Object-level access is recorded only by data events, which must have been enabled before the exposure. Management events record the configuration change rather than the reads. Current configuration says nothing about past access. Macie classifies content rather than recording access.

56. A compromised access key must be disabled immediately, and the team is unsure which principal owns it. Which approach is appropriate?

Answer and explanation

Answer: C. An access key identifier maps to its owning user, which is looked up directly and then deactivated. Deleting every key causes a widespread outage. An account-wide deny causes the same. Waiting leaves the compromised key active.

57. A ransomware incident requires restoring data while preserving the encrypted copies as evidence. Which approach is appropriate?

Answer and explanation

Answer: C. Restoring to a new location returns service while the affected data remains available for forensic analysis. Restoring over it or deleting it destroys evidence. Recovering an attacker's key is not a response plan.

58. An incident response plan must define how responders obtain elevated access during an incident. Which approach is appropriate?

Answer and explanation

Answer: C. A pre-provisioned break-glass role with alerting balances availability against visibility. Standing administrator access removes the control. Requesting access during an incident adds delay. Root credentials must never be shared.

59. An incident response plan must specify how evidence is preserved so it remains admissible. Which practice applies?

Answer and explanation

Answer: B. Chain of custody documentation is what preserves admissibility. Storing evidence in the affected account risks tampering. Compression and broad sharing do not address integrity or custody.

60. An incident response plan must be exercised without disrupting production. Which approach is appropriate?

Answer and explanation

Answer: B. A non-production environment or tabletop exercises the plan safely. Production exercises during peak risk users. A runbook review is not an exercise. Waiting for a real incident is not preparation.

61. An organization must define when a security event becomes a security incident. Which approach is appropriate?

Answer and explanation

Answer: A. Pre-agreed criteria produce consistent classification. Individual judgement varies. Treating every finding as an incident exhausts the response capacity. Waiting for leadership inverts the sequence.

62. An incident response capability must be able to isolate a compromised account within an organization. Which preparation is required?

Answer and explanation

Answer: C. A pre-authorized and tested restrictive policy isolates the account quickly. Removing the account from the organization removes the control that isolates it. Deleting users and changing the root password address only some access paths.

63. An EC2 instance must be preserved for forensic analysis while being removed from service. Which sequence is appropriate?

Answer and explanation

Answer: C. Isolation preserves state while stopping communication, memory is captured before any power event, and snapshots preserve disk. Terminating, rebooting, and restoring all destroy evidence.

64. A GuardDuty finding indicates credential exfiltration from an EC2 instance role. Which immediate action is appropriate?

Answer and explanation

Answer: D. Session revocation invalidates the exfiltrated credentials while preserving the role for investigation and legitimate use. Deleting the role breaks dependent configurations. Stopping the instance destroys volatile evidence. Root credentials are unrelated.

65. An S3 bucket's objects have been encrypted by an attacker using a key the organization does not control. Which recovery action is appropriate?

Answer and explanation

Answer: C. Restoring from versions or an isolated backup recovers the data while the encrypted copies remain as evidence. The organization's keys cannot decrypt content encrypted with the attacker's key. Deletion loses both data and evidence.

66. An automated response must contain a finding without an engineer approving each action. Which control keeps the automation safe?

Answer and explanation

Answer: C. Narrow permissions bound what an automated response can do, and logging makes every action reviewable. Administrator permissions make the automation itself a risk. An approval step removes the automation. A schedule decouples the response from the event.