SCS-C02 Threat Detection and Incident Response Practice Question
A security engineer is reviewing AWS CloudTrail and notices `AssumeRole` API calls to a role that should not be assumed by the source identity. What is the FIRST step in the incident response process?
⚠ Common exam trap
The trap here is that candidates often jump to containment actions like deleting the role or disabling the account, forgetting that the first step in incident response is always to investigate and gather evidence to confirm the threat and preserve forensic data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the source IP address and user agent of the `AssumeRole` calls.
The first step in any incident response process is to investigate and gather evidence to understand the scope and impact of the potential security event. Option C is correct because analyzing the source IP address and user agent of the `AssumeRole` API calls provides critical forensic data to determine if the activity is malicious or a false positive, without disrupting operations or destroying evidence. AWS CloudTrail logs these details, enabling the security engineer to trace the origin of the unauthorized assumption before taking any containment or remediation actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS GuardDuty to detect future anomalies.
Why it's wrong here
Enabling GuardDuty adds a detective control for future behavior, but it cannot surface details about the AssumeRole calls already present in CloudTrail, nor can it stop a currently active role session. Before enabling more alerting, the engineer must triage the logged events to determine whether the role was actually compromised and by whom. GuardDuty could be part of a later hardening step, but it is not the immediate incident-response action.
- ✗
Delete the IAM role immediately.
Why it's wrong here
Deleting the IAM role immediately would remove the role's trust policy, attached permissions, and CloudTrail's ability to correlate the role ARN with its configuration at the time of the incident, effectively destroying forensic evidence. It also disrupts any legitimate workloads that may use the role and does not invalidate temporary credentials already issued — those sessions remain valid for up to the role's duration limit unless explicitly revoked. The safer containment step is to deny usage for the suspected session, not delete the role.
- ✓
Investigate the source IP address and user agent of the `AssumeRole` calls.
Why this is correct
Investigating the source IP address and user agent of the AssumeRole calls is the correct first step because those fields are directly logged in the CloudTrail management event and let the engineer determine whether the role was assumed from an expected corporate network and application versus an unknown external host. This information can be cross-referenced with VPC Flow Logs, AWS WAF logs, or threat intelligence to establish a baseline of legitimate usage and scope the incident. It preserves all evidence while enabling a quick threat verdict.
- ✗
Disable the AWS account and contact support.
Why it's wrong here
Disabling the entire AWS account and contacting support is a disproportionate response that takes down all workloads and services, potentially causing a production outage while doing nothing to preserve or analyze the evidence already captured in CloudTrail. AWS Support cannot triage the incident faster than the security engineer can review the AssumeRole event's source and permissions, and an account disable may not even invalidate existing temporary credentials. The appropriate escalation is to first verify the threat, then apply targeted containment before contacting AWS Support if needed.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.