SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a potential security incident involving an Amazon RDS database. The engineer needs to identify which of the following actions should be taken during the forensic analysis phase? (Select TWO.)
⚠ Common exam trap
Watch out — candidates often confuse containment actions (like modifying security groups) with forensic preservation actions, leading candidates to select Option C instead of recognizing that the first step in forensic analysis is to capture immutable evidence via a snapshot and review CloudTrail logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Take a manual snapshot of the RDS instance.
Taking a manual snapshot preserves a point-in-time, immutable copy of the RDS instance for offline forensic analysis without altering the live database. This ensures that evidence is captured before any changes occur during the investigation, and the snapshot can be restored to a separate instance for safe examination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable automatic backups if not already enabled.
Why it's wrong here
Enabling automatic backups only affects future RDS backup windows and cannot retroactively capture data that existed before the setting was enabled. If the incident began before this change, no automated backup of the compromised state will exist, and thus this action provides no forensic value. Manual snapshots, by contrast, preserve the current database state immediately for later analysis.
- ✗
Disable deletion protection to allow cleanup.
Why it's wrong here
Disabling deletion protection removes a safety control that prevents accidental or malicious deletion of the RDS instance. Doing so during an active investigation risks destroying the very database that may hold evidence, and it is not part of evidence acquisition. While this might be considered during remediation, it is not a forensic step and should be delayed until after the investigation completes.
- ✗
Modify the security group to restrict database access.
Why it's wrong here
Modifying the security group to restrict database access is a containment measure that limits who can connect to the RDS instance, but it does not capture or preserve any database state for forensics. In fact, changing network controls could alter the environment's observable behavior and may alert the attacker, potentially before a snapshot is taken. The priority should be to create a forensic copy and collect audit logs before any changes are made.
- ✓
Take a manual snapshot of the RDS instance.
Why this is correct
A manual snapshot immediately captures a consistent, point-in-time copy of the RDS instance, including its data, storage configuration, and parameters, independent of the automated backup window. This snapshot can be stored even if automatic backups are disabled, and it can later be restored to an isolated instance for forensic analysis without affecting the original. It is the correct first step to preserve volatile database evidence that could otherwise be modified or deleted during the investigation.
- ✓
Review AWS CloudTrail logs for API calls related to the RDS instance.
Why this is correct
CloudTrail logs record control-plane API calls made against the RDS instance, such as DescribeDBInstances, ModifyDBInstance, CreateDBSnapshot, and DeleteDBInstance, along with the IAM principal, source IP, user agent, and timestamp. Reviewing these logs can reveal exactly who performed actions on the RDS instance and when, providing critical evidence about attacker behavior. This is complementary to a manual snapshot because it establishes the sequence of administrative actions rather than preserving the database's data state.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.