SCS-C03 · domain
Incident Response
Practise AWS Certified Security - Specialty Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Incident Response questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Incident Response
Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Incident Response exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Incident Response questions (12)
Click any question to see the full explanation, or start a practice session above.
During a security incident involving suspected data exfiltration from an S3 bucket, which THREE sources provide the most relevant telemetry to determine what files were accessed?
Medium2Your company has a multi-account environment managed by AWS Organizations. A security incident reveals that a member account has been compromised. You must prevent the attacker from disabling CloudTrail or deleting logs in that account while maintaining central visibility. What is the most effective approach?
Hard3An incident response team discovers an unauthorized IAM user created an access key in a production environment. The team must identify the exact time of key creation and the IP address used for the call. Which AWS service provides this forensic detail?
Medium4Refer to the exhibit. An incident responder needs to access the production-data bucket to investigate a breach. They apply this policy to their IAM user, but get 'Access Denied' when running 'aws s3 ls s3://production-data'. Why?
Hard5An organization wants to improve their ability to respond to security incidents. Which TWO of the following services provide centralized visibility and management for security findings?
Medium6An organization is preparing for a potential incident and wants to ensure that responders can quickly access logs across multiple accounts. Which architecture is recommended for centralized log management?
Hard7An organization's security team detects an active data exfiltration event originating from a compromised Amazon EC2 Linux instance. The instance contains critical forensic evidence that must be preserved. What is the most effective immediate containment action that prevents external communication while retaining the memory state for forensic analysis?
Medium8A security incident indicates an EC2 instance is likely compromised and communicating with a C2 server. The security team needs to perform memory forensics and isolate the instance while preserving evidence. Which TWO actions should the team perform?
Hard9An organization detects unauthorized access to an Amazon S3 bucket containing sensitive customer data. The Security team needs to immediately isolate the bucket while ensuring logs are preserved for forensic analysis. Which action should the team take first?
Medium10A security engineer investigating a security alert discovers that an IAM role in an AWS account has been modified by an unknown external entity. The engineer needs to determine the exact API call that introduced the malicious policy change and identify the associated source IP address. Which AWS service provides the most definitive and historically accurate audit trail for this investigation?
Hard11Refer to the exhibit. An incident responder observes that an attacker bypassed this S3 bucket policy and accessed objects from an IP address outside the 192.0.2.0/24 range. What is the most likely reason for this access?
Medium12An organization experiences a ransomware attack that encrypts data across several EBS volumes. The team needs to restore operations as quickly as possible. Which strategy minimizes the impact of the incident while ensuring data integrity?
MediumOther domains
All SCS-C03 exam domains
Frequently asked questions
- What does the Incident Response domain cover on the SCS-C03 exam?
- Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 12 Incident Response questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Incident Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.