Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is building an incident response playbook for compromised IAM credentials. The engineer wants to automatically revoke access and preserve evidence when an access key is suspected of being compromised. Which TWO actions should be included in the playbook? (Choose two.)

⚠ Common exam trap

The trap here is choosing to delete the compromised IAM user, which feels decisive but destroys the metadata and audit trail needed for the investigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deactivate the access key and attach an explicit deny policy to the IAM user to prevent any further API calls.

A credential compromise playbook must both revoke access and preserve evidence. Deactivating the key and attaching an explicit deny policy stops further API calls immediately while keeping the identity intact for analysis. Capturing the user's policies, key metadata, and recent CloudTrail events before changes preserves the activity history needed to determine impact and support notifications. Deleting the user, rotating the key, or disabling logging would destroy evidence or fail to revoke access effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate the access key by creating a new key and attaching it to the same IAM user, then delete the old key.

    Why it's wrong here

    Creating a new key for the same user does not revoke the compromised key's ability to be used until the old key is deleted, and deletion still removes evidence. Rotation is a hygiene practice, not an incident response action, and it does not address the need to preserve forensic artifacts or block the user's other credentials.

  • ✓

    Deactivate the access key and attach an explicit deny policy to the IAM user to prevent any further API calls.

    Why this is correct

    Deactivating the access key immediately stops its use, and attaching an explicit deny policy blocks the user from making further calls with any credentials or sessions. This revokes access quickly while preserving the key's metadata and the user's configuration for later analysis, which supports evidence preservation.

  • ✓

    Capture the current IAM user policy, access key metadata, and recent CloudTrail events for the key before making changes.

    Why this is correct

    Recording the user's policies, key metadata, and recent CloudTrail events before remediation preserves the state and activity history needed for investigation. This evidence can show what the compromised key did, which resources were accessed, and whether the activity was malicious, supporting both the incident report and any required notifications.

  • ✗

    Delete the IAM user and all associated access keys to ensure the compromised identity cannot be used again.

    Why it's wrong here

    Deleting the IAM user removes the identity and its metadata, which destroys evidence such as the key's creation date, last-used information, and attached policies. It also prevents investigation of what the credentials accessed, and it is irreversible, making it unsuitable for a playbook that must preserve evidence.

  • ✗

    Disable AWS CloudTrail logging to prevent the attacker from observing the security team's remediation actions.

    Why it's wrong here

    Disabling CloudTrail logging destroys the audit trail and prevents the team from tracking the attacker's activity and verifying remediation. Attackers cannot read CloudTrail logs unless granted permissions, so this action provides no security benefit and actively harms the investigation and compliance posture.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.