SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is investigating a suspected compromise of an Amazon EC2 instance that is a member of an Auto Scaling group. The instance is still running and the engineer must preserve volatile evidence before the Auto Scaling group replaces it. Which sequence of actions best preserves the evidence while maintaining the ability to analyze it later?
⚠ Common exam trap
The trap here is treating an AMI or EBS snapshot as complete evidence and terminating the instance, which destroys volatile memory and any live network state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture memory with an approved forensic tool, take EBS snapshots of all attached volumes, record instance metadata and network connections, then isolate the instance by replacing its security group with a quarantine group.
Preserving volatile evidence requires acting before any shutdown or termination. Capturing memory first retains processes and credentials, EBS snapshots preserve disk state for offline analysis, and recording metadata and network connections provides investigative context. Isolating the instance with a quarantine security group stops exfiltration and command-and-control traffic without destroying the evidence, and it keeps the instance alive so additional artifacts can be collected if needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stop the instance, detach the root EBS volume, create a snapshot of the volume, and then reattach the original volume to the instance.
Why it's wrong here
Stopping the instance loses volatile memory contents and the Auto Scaling group may terminate and replace the instance during the stop. Detaching and reattaching the root volume also risks corrupting the filesystem if the instance is brought back up with a changed device mapping, and it does not capture memory or network state.
- ✗
Create an AMI of the instance, terminate the instance to prevent further malicious activity, and launch a new instance from the AMI for analysis.
Why it's wrong here
Creating an AMI captures disk state but not memory or live network connections, and terminating the instance destroys all volatile evidence. Terminating also prevents collection of additional artifacts such as running processes or open file handles, and the AMI may not include data written to instance store volumes.
- ✗
Detach the instance from the Auto Scaling group, reboot the instance into single-user mode, and copy the root filesystem to an S3 bucket using the AWS CLI.
Why it's wrong here
Rebooting discards volatile memory and may allow the attacker's persistence mechanisms to run again. Copying files to S3 from within the potentially compromised instance risks tampering with evidence and does not capture memory or network state, and single-user mode does not guarantee a clean forensic image.
- ✓
Capture memory with an approved forensic tool, take EBS snapshots of all attached volumes, record instance metadata and network connections, then isolate the instance by replacing its security group with a quarantine group.
Why this is correct
Capturing memory first preserves volatile data such as running processes and credentials that are lost on shutdown. EBS snapshots of all volumes preserve persistent disk state, and recording metadata and network connections captures context. Isolating with a quarantine security group stops further communication without destroying the instance, giving the engineer time to analyze copies.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.