Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security engineer receives an Amazon GuardDuty finding for 'UnauthorizedAccess:EC2/SSHBruteForce'. The engineer needs to automatically isolate the compromised EC2 instance and then perform forensic analysis. Which solution meets these requirements with the LEAST operational overhead?

⚠ Common exam trap

Many exam-takers assume manual SSH or AWS Config rules are sufficient for incident response, but they fail to recognize that GuardDuty findings require automated, event-driven isolation without human intervention, and that Config rules lack the ability to trigger real-time security group modifications or snapshots.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Amazon EventBridge rule that triggers an AWS Lambda function to isolate the instance by modifying its security group and then take a forensic snapshot.

It automates the isolation and forensic capture of the compromised EC2 instance with minimal operational overhead. An Amazon EventBridge rule listens for the specific GuardDuty finding and triggers an AWS Lambda function that modifies the instance's security group to deny all inbound/outbound traffic (isolation) and then creates an EBS snapshot for forensic analysis. This serverless, event-driven approach eliminates manual intervention and ensures consistent, rapid response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually SSH into the instance, stop it, and create an AMI for analysis.

    Why it's wrong here

    Manually SSHing into the instance and stopping it is not a scalable or automated response to a GuardDuty finding. The very act of SSHing into a compromised host can alter volatile state and destroy forensically relevant evidence, while stopping the instance may preserve disk, but the manual process introduces significant delay and requires individuals to be available. Creating an AMI manually also fails to isolate the instance from the network, so it may remain active and communicating with an attacker throughout the response.

  • ✓

    Create an Amazon EventBridge rule that triggers an AWS Lambda function to isolate the instance by modifying its security group and then take a forensic snapshot.

    Why this is correct

    This is the correct response because Amazon EventBridge can be configured to receive GuardDuty findings as events, triggering a Lambda function for immediate, automated response. The Lambda function can modify the instance's security group to deny all ingress and egress traffic, effectively isolating it while preserving the running state and memory for analysis. A subsequent snapshot of the EBS volumes provides a forensically sound copy for offline investigation, all without manual intervention or risk of contaminating the evidence.

  • ✗

    Use AWS Config rules to automatically stop the instance.

    Why it's wrong here

    AWS Config is designed for configuration compliance and change management, not for real-time threat response to GuardDuty findings. Config rules evaluate resource configurations against desired policies and can trigger remediation actions, but they rely on configuration changes and are not event-driven or responsive enough for security incidents. Stopping an instance also causes loss of volatile memory data and does not provide the same network isolation and forensic capture as modifying the security group and snapshotting the EBS volumes.

  • ✗

    Configure an Auto Scaling lifecycle hook to terminate the instance and launch a new one.

    Why it's wrong here

    Auto Scaling lifecycle hooks are intended for gracefully executing custom actions during scale-in or scale-out events, not for responding to security findings. Terminating the instance immediately destroys any volatile evidence and makes forensic analysis impossible, even if a new instance is launched. This approach also fails to isolate the instance first, meaning the attacker could still move laterally before termination, and the response is not configurable to take a snapshot prior to destruction.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.