SCS-C02 Management and Security Governance Practice Question
A company's security team discovers that an EC2 instance in the production account has been compromised. The instance has an IAM role attached that allows it to read from an S3 bucket containing sensitive data. The team needs to immediately stop the data exfiltration while preserving the evidence. What should the team do first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an inline policy to the IAM role that denies all S3 actions.
The correct first step because applying an inline policy that denies all S3 actions to the IAM role immediately stops the compromised instance from accessing the S3 bucket, preventing data exfiltration while preserving the instance's state for forensic investigation. Option A is incorrect because detaching the S3 bucket from the VPC endpoint does not affect the instance's ability to access S3 through the internet or other endpoints. Option C is incorrect because removing the IAM role from the instance may not take effect immediately if the role's credentials are cached, and it could disrupt evidence collection. Option D is incorrect because terminating the instance would destroy volatile evidence and might not stop exfiltration in time if the instance is already sending data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detach the S3 bucket from the VPC endpoint.
Why it's wrong here
Detaching the S3 bucket from the VPC endpoint does not revoke the IAM role's permissions; the endpoint is simply a network path, and the instance may still reach S3 over the public internet or a NAT gateway. This action also affects every other resource using the endpoint, causing widespread disruption, and it does not prevent the compromised credentials from being used from another location. Thus it is not a targeted containment measure.
- ✓
Apply an inline policy to the IAM role that denies all S3 actions.
Why this is correct
Attaching an inline policy with an explicit deny for all S3 actions to the EC2 instance's IAM role immediately blocks all S3 API calls because explicit denies override any allow statements, and IAM policies are evaluated at request time. This containment works for any temporary credentials already issued, since every request is re-authorized against the role's current policies, and it does not destroy the instance or remove evidence needed for investigation. This is the fastest, least invasive way to stop S3 exfiltration.
- ✗
Remove the IAM role from the EC2 instance.
Why it's wrong here
Removing the IAM role from the instance only detaches the instance profile, but credentials that were already delivered to the instance via the instance metadata service remain valid until their expiration, which can be up to six hours. During that window, any process or attacker can still use those cached temporary credentials to access S3, so the action is not immediate and may also break legitimate applications that depend on the role. An explicit deny policy on the role is more effective because it is evaluated at every request.
- ✗
Terminate the compromised EC2 instance immediately.
Why it's wrong here
Terminating the compromised EC2 instance immediately destroys all running processes, EBS volumes, and memory contents, eliminating crucial forensic evidence and making it impossible to determine how the attack occurred or what data was accessed. It also does not revoke the instance's IAM role permissions, so any temporary credentials previously obtained could still be used externally until they expire. Proper incident response requires isolating the instance while preserving evidence and revoking access via IAM policies.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.