Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer is investigating a potential compromise of an EC2 instance. The engineer wants to capture volatile memory data and create a forensic image of the instance's EBS volumes. Which TWO actions should the engineer take? (Choose 2.)

⚠ Common exam trap

Test-takers frequently confuse AWS Backup (a managed backup service) with EBS snapshots, not realizing that AWS Backup does not provide the immediate, point-in-time forensic snapshot needed for incident response and may introduce additional latency or metadata changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Run Command to execute a memory capture script.

AWS Systems Manager Run Command allows you to remotely execute scripts on EC2 instances without needing SSH access, which is critical during incident response to capture volatile memory data before the instance is compromised further. Option D is correct because creating an EBS snapshot provides a point-in-time forensic image of the root volume that can be analyzed offline without altering the original evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS CloudTrail for the instance.

    Why it's wrong here

    Enabling AWS CloudTrail records management/control-plane API actions in the region going forward, such as RunInstances or AttachVolume, but it has no visibility into the guest kernel or memory. CloudTrail also requires past events to have been enabled beforehand; simply enabling it now cannot retroactively reveal the instance's volatile memory content. A memory forensics capture requires an in-guest agent or hypervisor-level access, not API activity logs.

  • ✓

    Use AWS Systems Manager Run Command to execute a memory capture script.

    Why this is correct

    Run Command uses the AWS Systems Manager (SSM) agent already installed on the instance to execute a locally supplied script, so you can run a memory acquisition tool like LiME (Linux) or WinPmem (Windows), save the memory image to a file, and upload it to Amazon S3 for analysis. Because Run Command executes without terminating or rebooting the instance, the volatile state is preserved, which is crucial for retrieving running processes, loaded kernel modules, and open network connections. The SSM agent must be running, and the instance profile needs SSM permissions and access to the destination S3 bucket.

  • ✗

    Use AWS Backup to create a backup of the instance.

    Why it's wrong here

    AWS Backup is a scheduled backup service designed to create recoverable EBS snapshots on a backup schedule, typically to support restoration and disaster recovery, not to perform forensic data acquisition. A Backup-created snapshot only contains disk blocks, never memory, and using it doesn't produce an evidence-grade image with a forensic chain of custody. If you need a disk forensics copy, create an explicit EBS snapshot to control timing, preserve integrity, and capture only the disk state.

  • ✓

    Create an Amazon EBS snapshot of the instance's root volume.

    Why this is correct

    Creating an Amazon EBS snapshot of the root volume captures the disk's state at a precise moment, giving you a non-volatile forensic copy that can be attached to a quarantine instance for postmortem analysis without touching the original. This is correct for disk forensics, but it does not contain the instance's memory, so volatile artifacts like encryption keys in RAM, in-memory malware, and cached credentials are lost. Snapshot data is replicated in S3, but the running instance's memory is isolated from the EBS volume and is not included.

  • ✗

    Use Amazon Inspector to scan the instance for vulnerabilities.

    Why it's wrong here

    Amazon Inspector runs agent-based assessments for known vulnerabilities, unintended network exposure, and drift against security benchmarks; it does not perform any memory capture. Inspector makes network calls and process queries to identify risks, but it won't preserve a memory dump and could even alter evidence if run during an investigation. It's a vulnerability management tool, not a forensic acquisition tool, so it does not help recover the volatile memory content needed for this compromise investigation.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.