SCS-C02 Amazon EBS snapshot Practice Question
A security engineer is investigating a security incident where an EC2 instance was used to launch an outbound denial-of-service (DoS) attack. The engineer needs to collect forensic evidence. Which THREE actions should the engineer take? (Choose three.)
⚠ Common exam trap
A common pitfall is selecting options like rebooting (A) or deleting logs (B) which destroy evidence. While terminating (E) is a valid containment step, it must be done after evidence is collected via snapshot (C) and memory capture (D). The three correct actions are C, D, and E.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Amazon EBS snapshot of the instance's root volume.
Creating an Amazon EBS snapshot preserves persistent data for offline analysis. Option D is correct because capturing memory preserves volatile evidence. Option E is correct because after collecting forensic evidence, terminating the instance stops the attack immediately and prevents further damage. Options A and B are incorrect because they destroy evidence (reboot clears memory, deletion removes logs).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the instance to clear any malicious processes.
Why it's wrong here
Rebooting the instance will clear memory, destroying all volatile evidence such as running processes, network connections, and in-memory malware, which is the opposite of a proper forensic response. It also gives the attacker's persistence mechanisms a chance to re-trigger or cause the instance to hang or malfunction. Reboot should only be considered after memory capture and disk snapshot have been completed, if at all.
- ✗
Delete the CloudTrail logs that show the instance's API calls.
Why it's wrong here
Deleting CloudTrail logs removes the authoritative record of API calls made against the instance and the account, including who launched it, modified security groups, or accessed the console. This destroys critical forensic evidence and is itself an auditable event, so the deletion may be recorded in a separate log or in the same trail before removal. It also violates the principle of evidence preservation and can ruin legal admissibility, so this action is never appropriate during an incident.
- ✓
Create an Amazon EBS snapshot of the instance's root volume.
Why this is correct
Creating an EBS snapshot of the root volume captures the disk state at a single point in time, including compromised binaries, log files, user artifacts, and any persistence mechanisms the attacker installed. Unlike live acquisition, a snapshot allows offline analysis on a separate instance without altering the original evidence. It also provides a recoverable copy in case the instance is later terminated for containment.
- ✓
Capture the instance's memory using a tool like LiME or Amazon EC2 instance memory capture.
Why this is correct
Memory capture with LiME or the EC2 memory capture feature preserves volatile data such as running processes, loaded kernel modules, open network connections, and in-memory artifacts like rootkits or injected code. This evidence disappears the instant the instance is stopped, rebooted, or terminated, so capture must occur first. Because attackers often operate entirely in memory, this step is indispensable for building a complete forensic timeline.
- ✓
Terminate the instance to stop the attack immediately.
Why this is correct
Terminating the instance is a legitimate containment step, but only after memory and disk evidence have been preserved, because shutdown destroys volatile memory. Once snapshots and memory capture are complete, termination immediately stops the attacker's ongoing resource abuse, prevents further data exfiltration, and halts any cryptomining or lateral movement. Doing it earlier would destroy the very evidence needed to understand the breach.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.