Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

A security team is implementing automated response to AWS GuardDuty findings. Which THREE actions should be taken to ensure proper incident response?

⚠ Common exam trap

Watch out — candidates often think immediate termination (Option D) is the fastest way to neutralize a threat, but AWS incident response frameworks emphasize containment and evidence preservation over destruction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an AWS Lambda function that automatically modifies the security group of the affected instance to block all traffic.

Isolating the affected instance by modifying its security group to block all traffic is a common containment strategy that stops malicious network activity without destroying evidence. This approach allows the security team to perform forensic analysis and remediation while preventing further compromise, aligning with AWS incident response best practices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an AWS Lambda function that automatically modifies the security group of the affected instance to block all traffic.

    Why this is correct

    Automating a Lambda-based containment action via EventBridge when a GuardDuty finding is detected is the correct initial response because it lets you immediately revoke all inbound and outbound security group rules on the affected instance. This stops lateral movement and malicious traffic while leaving the instance running and its memory and disk state intact for later forensic collection. The Lambda function must have the appropriate IAM policy to describe and modify security groups, and it can also log the rule changes to CloudTrail for audit.

  • ✓

    Tag the affected instance with a 'quarantine' tag for tracking.

    Why this is correct

    Assigning a dedicated 'quarantine' tag to the affected instance is a best practice for incident management because it creates an auditable, trackable marker that all response tools and teams can use to identify the scope of the incident. The tag can trigger automated workflows, such as Lambda functions that isolate the instance or SNS notifications to the incident response team, and it simplifies post-incident cost allocation and compliance reporting. This step is complementary to containment, as it does not itself stop traffic but enables structured and repeatable response actions.

  • ✓

    Create a snapshot of the EBS volumes attached to the instance for forensic analysis.

    Why this is correct

    Creating a point-in-time snapshot of the EBS volumes attached to the affected instance preserves volatile and non-volatile evidence at a specific moment, which is essential for forensic analysis and legal hold. The snapshot can later be mounted to a clean forensic instance without altering the original evidence, allowing investigators to analyze file system artifacts, malware, and attacker activity safely. Because snapshots are asynchronous, you should trigger this action immediately after isolation and before making any changes to the instance to ensure the evidence is not contaminated.

  • ✗

    Terminate the affected instance immediately to neutralize the threat.

    Why it's wrong here

    Terminating the affected instance immediately is not the correct containment action because it destroys the running memory contents and makes forensic analysis of the root cause, attacker tactics, and persistence mechanisms extremely difficult or impossible. While it would stop the threat, it is a destructive action that removes the ability to identify other compromised resources or recover from a deeper compromise, and it may also cause unintended business disruption. Proper response sequencing prescribes containing traffic via security groups first, then preserving evidence with snapshots, and only terminating after analysis is complete.

  • ✗

    Disable AWS CloudTrail to prevent further logging of malicious activity.

    Why it's wrong here

    Disabling AWS CloudTrail to stop further logging is a dangerous and incorrect response because CloudTrail records the API activity that investigators need to retrace the attack, and turning it off would immediately reduce visibility into the attacker's actions and may itself be considered a sign of malicious tampering. CloudTrail logs are immutable and can be stored in S3 with enforcement via SCPs or IAM policies, so disabling the trail does not erase past evidence but does prevent future logs that are crucial for incident reconstruction. The correct procedure is to keep CloudTrail enabled and instead use the logs to analyze the incident while using other mechanisms (such as security group changes) to contain the threat.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.