20+ practice questions focused on Threat Detection and Incident Response — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Threat Detection and Incident Response PracticeDuring an incident response, a security engineer needs to collect memory and disk forensics from a running EC2 Windows instance without causing the instance to crash. The engineer has AWS Systems Manager SSM Agent installed. Which method should the engineer use?
Explanation: An EBS snapshot provides a forensic copy of the root volume but cannot capture volatile memory (RAM). To collect memory forensics, the engineer must run a memory dump tool via SSM Run Command before taking the snapshot. Since none of the options include a memory capture method, the question should be revised to either ask specifically for disk forensics or add an option for memory capture. As written, the question is invalid.
A security engineer is investigating a potential data exfiltration incident. The engineer notices large volumes of data being transferred from an Amazon S3 bucket to an external IP address. Which AWS services can be used to detect and alert on such behavior? (Choose THREE.)
Explanation: Amazon CloudWatch Logs with S3 access log analysis (A) is correct because S3 server access logs record every request made to a bucket, including the requester's IP address and bytes sent, and CloudWatch Logs metric filters and alarms can detect and alert on unusually large data transfers to external IPs. AWS CloudTrail with S3 data event logging (B) is correct because data events capture object-level operations such as GetObject, and CloudTrail can deliver these events to CloudWatch Logs or EventBridge for anomaly-based alerting on suspicious exfiltration patterns. Amazon GuardDuty with anomaly detection (C) is correct because GuardDuty continuously analyzes CloudTrail management and data events, VPC Flow Logs, and DNS logs using machine learning and threat intelligence to generate findings such as Exfiltration:S3/AnomalousBehavior or UnauthorizedAccess. AWS Config with compliance rules (D) is not correct because Config evaluates resource configuration compliance against rules and does not detect or alert on live data-transfer behavior. VPC Flow Logs (E) is not correct because it captures IP traffic metadata for network interfaces and cannot inspect S3 object-level API activity or identify data exfiltration from a bucket.
A company runs a critical web application on a fleet of EC2 instances behind an Application Load Balancer (ALB). The application uses an Aurora MySQL database. The security team receives an alert from Amazon GuardDuty that a specific EC2 instance is exhibiting behavior consistent with a cryptocurrency mining attack, including outbound connections to known mining pools. The instance is part of an Auto Scaling group that uses a launch template with a security group that allows outbound HTTPS traffic to 0.0.0.0/0. The security engineer needs to contain the incident while minimizing downtime for the application. The engineer has already taken a forensic snapshot of the instance's EBS volume. Which course of action should the engineer take next?
Explanation: The correct course of action is to isolate the compromised instance without disrupting the rest of the fleet. Detaching the instance from the Auto Scaling group removes it from management and triggers a replacement to maintain capacity. Removing or replacing its security group rules (or attaching a quarantine security group) halts all traffic, including outbound communication to mining pools. This contains the threat while minimizing downtime. Option A is wrong because the security group is defined in the launch template and is shared across all instances; modifying it would block outbound traffic for the entire application, causing a full outage. Option D is less ideal because immediate termination loses the ability to conduct further live forensics (though a snapshot exists) and may be hasty without first isolating the instance.
Match each AWS IAM policy type to its description.
Explanation: The correct matches are: Identity-based policies are attached to users, groups, or roles; Resource-based policies are attached to resources; Permissions boundaries limit maximum permissions; Session policies are passed during role assumption. Common confusions include swapping identity-based and resource-based definitions.
A company wants to ensure that any deleted CloudTrail logs are detected and alerted within minutes. Which approach should they use?
Explanation: CloudTrail management events (including DeleteTrail) are delivered to CloudWatch Logs, where a metric filter can match the exact event name. A CloudWatch alarm on that metric triggers an SNS notification within minutes, meeting the detection and alerting requirement. This approach directly monitors the CloudTrail API call that deletes the trail itself, not just the log files.
+15 more Threat Detection and Incident Response questions available
Practice all Threat Detection and Incident Response questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Threat Detection and Incident Response. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Threat Detection and Incident Response questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Threat Detection and Incident Response is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Threat Detection and Incident Response questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Threat Detection and Incident Response is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Threat Detection and Incident Response practice session with instant scoring and detailed explanations.
Start Threat Detection and Incident Response Practice →