Courseiva

SCS-C03 · domain

Incident Response

Practise AWS Certified Security - Specialty Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

12 questions7 medium5 hard

Focused practice

Practice Incident Response questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Incident Response

Incident Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Incident Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Incident Response questions (12)

Click any question to see the full explanation, or start a practice session above.

1

During a security incident involving suspected data exfiltration from an S3 bucket, which THREE sources provide the most relevant telemetry to determine what files were accessed?

Medium
2

Your company has a multi-account environment managed by AWS Organizations. A security incident reveals that a member account has been compromised. You must prevent the attacker from disabling CloudTrail or deleting logs in that account while maintaining central visibility. What is the most effective approach?

Hard
3

An incident response team discovers an unauthorized IAM user created an access key in a production environment. The team must identify the exact time of key creation and the IP address used for the call. Which AWS service provides this forensic detail?

Medium
4

Refer to the exhibit. An incident responder needs to access the production-data bucket to investigate a breach. They apply this policy to their IAM user, but get 'Access Denied' when running 'aws s3 ls s3://production-data'. Why?

Hard
5

An organization wants to improve their ability to respond to security incidents. Which TWO of the following services provide centralized visibility and management for security findings?

Medium
6

An organization is preparing for a potential incident and wants to ensure that responders can quickly access logs across multiple accounts. Which architecture is recommended for centralized log management?

Hard
7

An organization's security team detects an active data exfiltration event originating from a compromised Amazon EC2 Linux instance. The instance contains critical forensic evidence that must be preserved. What is the most effective immediate containment action that prevents external communication while retaining the memory state for forensic analysis?

Medium
8

A security incident indicates an EC2 instance is likely compromised and communicating with a C2 server. The security team needs to perform memory forensics and isolate the instance while preserving evidence. Which TWO actions should the team perform?

Hard
9

An organization detects unauthorized access to an Amazon S3 bucket containing sensitive customer data. The Security team needs to immediately isolate the bucket while ensuring logs are preserved for forensic analysis. Which action should the team take first?

Medium
10

A security engineer investigating a security alert discovers that an IAM role in an AWS account has been modified by an unknown external entity. The engineer needs to determine the exact API call that introduced the malicious policy change and identify the associated source IP address. Which AWS service provides the most definitive and historically accurate audit trail for this investigation?

Hard
11

Refer to the exhibit. An incident responder observes that an attacker bypassed this S3 bucket policy and accessed objects from an IP address outside the 192.0.2.0/24 range. What is the most likely reason for this access?

Medium
12

An organization experiences a ransomware attack that encrypts data across several EBS volumes. The team needs to restore operations as quickly as possible. Which strategy minimizes the impact of the incident while ensuring data integrity?

Medium

Frequently asked questions

What does the Incident Response domain cover on the SCS-C03 exam?
Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 12 Incident Response questions in the SCS-C03 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Incident Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
AWS Certified Security - Specialty SCS-C03 Incident Response Practice Questions