Courseiva

DOP-C02 Incident and Event Response Practice Question

A company experiences a security incident where an IAM user's access key is compromised. Which THREE steps should the DevOps engineer take immediately?

⚠ Common exam trap

DOP-C02 often tests whether candidates conflate console password compromise with access key compromise — the trap is choosing 'change the password' when the credential at risk is the API key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review AWS CloudTrail logs for any unauthorized API calls

Option A is correct because AWS CloudTrail records all API activity in the account, so reviewing its logs lets the engineer identify unauthorized calls made with the compromised access key and assess the incident's scope. Option B is correct because rotating the access key—creating a new key pair and deleting the compromised key—immediately invalidates the leaked credential so it can no longer be used for API authentication. Option E is correct because if the compromised IAM user had assumed roles or obtained temporary credentials via STS, those session tokens remain valid until expiry, so they must be explicitly revoked (e.g., by attaching a deny-all policy or using AWSRevokeOlderSessions) to cut off the attacker's access. Option C does not belong because changing the IAM user's console password does not affect the compromised access key, which is used for programmatic API calls rather than console sign-in. Option D does not belong because deleting and recreating the IAM user is a disruptive, unnecessary step that would break existing permissions and resource associations; rotating the key and revoking sessions is sufficient to contain the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Review AWS CloudTrail logs for any unauthorized API calls

    Why this is correct

    AWS CloudTrail records all IAM user and role API activity as events, including the source IP address, user agent, event name, and whether the call was authorized. Analyzing CloudTrail logs with querying or visualization tools helps you identify which unauthorized or anomalous calls occurred, when they occurred, and what resources were accessed, so you can scope the impact and determine whether other remediation steps are needed. It is the first responder's forensic tool for understanding the security incident.

  • ✓

    Rotate the access key by creating a new key and deleting the old one

    Why this is correct

    An access key pair consists of an access key ID and a secret access key used for programmatic AWS API calls, and the only way to invalidate a compromised long-term key is to rotate it. Create a new access key for the IAM user, update any applications that use the old key, then delete the old key; alternatively, you can mark the old key as inactive to immediately deny its use while you prepare for deletion. This ensures the leaked secret no longer authenticates requests.

  • ✗

    Change the IAM user's password

    Why it's wrong here

    The IAM password authenticates the user only to the AWS Management Console, not to the AWS API or CLI, which rely on access keys or temporary credentials. Since the incident centers on an access key compromise, resetting the password does not invalidate or revoke the exposed access key, so unauthorized API calls would continue regardless of the new password. It only addresses the separate console login factor, making it an ineffective sole response.

  • ✗

    Delete the IAM user and recreate it

    Why it's wrong here

    Deleting and recreating the IAM user is far too disruptive and goes beyond the principle of least-damage remediation; you would lose the user's attached policies, group memberships, and any service-specific resources, and all permissions would need to be manually reconstructed. It also breaks any billing, reporting, or cross-service roles that reference the user by ARN. Since a compromised access key can be neutralized with key rotation alone (and active sessions can be revoked), deleting the user unnecessarily creates availability and administrative overhead.

  • ✓

    Revoke any temporary security credentials issued to the user

    Why this is correct

    Temporary credentials issued via STS, such as AssumeRole or GetFederationToken, have a fixed lifetime but can be actively revoked by attaching a policy to the role (or explicitly denying by token issue time) that denies actions when the session's `aws:TokenIssueTime` is earlier than a specified cutoff. Revoking these credentials invalidates all currently active sessions and forces callers to request new temporary credentials, but this mechanism does not apply to IAM users' long-term access keys. This step closes any live session that relies on the compromised identity before rotating static keys.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.