Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential compromise of an EC2 instance. The instance was launched from a custom AMI. The engineer needs to determine if the AMI itself contains malicious software. Which approach provides the most thorough analysis without risking the production environment?

⚠ Common exam trap

A common mix-up: candidates choose Option D (behavioral analysis) because it seems more hands-on and thorough, but they overlook that Amazon Inspector provides a more systematic, automated, and comprehensive scan for known vulnerabilities and misconfigurations, which is the most efficient way to identify malicious software in an AMI without risking the production environment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Launch a test instance from the AMI in an isolated VPC and run Amazon Inspector.

Launching a test instance from the AMI in an isolated VPC allows you to run Amazon Inspector, which performs automated vulnerability assessments and network reachability checks against the instance. This approach provides a thorough analysis of the AMI's software and configuration without exposing the production environment to any potential malicious activity. Amazon Inspector uses a knowledge base of common vulnerabilities and exposures (CVEs) and CIS benchmarks to identify security issues, making it effective for detecting malicious software embedded in the AMI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Launch a test instance from the AMI in an isolated VPC and run Amazon Inspector.

    Why this is correct

    Launching an isolated test instance from the AMI prevents any risk to production resources while allowing deep inspection. Amazon Inspector automatically assesses the instance for software vulnerabilities and unintended network exposure, producing a prioritized list of findings. This approach gives a clean, controlled environment for forensics without altering the original evidence.

  • ✗

    Use AWS Systems Manager to run a compliance scan on the running instance.

    Why it's wrong here

    A compliance scan via Systems Manager on the live instance is unreliable because a compromised host may have tampered agents, logs, or kernel state, making the scan results deceptive. Furthermore, SSM compliance checks configuration baselines rather than performing a comprehensive vulnerability and CVE analysis of the AMI's software packages. The instance itself could also be affected by ongoing malicious activity, so isolating a copy is necessary.

  • ✗

    Create an EBS snapshot from the AMI and scan the snapshot with Amazon Detective.

    Why it's wrong here

    Amazon Detective is built to analyze telemetry such as VPC Flow Logs, AWS CloudTrail, and GuardDuty findings to identify root cause, not to scan EBS snapshots for vulnerabilities. Creating a snapshot from the AMI preserves the block-level state, but no native AWS service scans snapshots directly; you must launch a compute instance from it to run Inspector. Thus, this option misunderstands Detective's purpose.

  • ✗

    Launch a test instance from the AMI in an isolated VPC and analyze its behavior.

    Why it's wrong here

    While launching a test instance in an isolated VPC and observing its behavior can reveal suspicious processes or network calls, it is entirely manual and does not systematically identify known software vulnerabilities. Behavior analysis may miss dormant threats or CVEs that Amazon Inspector automatically detects by inspecting installed packages and configurations. For a thorough, evidence-based assessment, you need both isolation and an automated scanning layer.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.