Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

During a security incident, a security engineer needs to collect EBS snapshots of multiple EC2 instances across different accounts in AWS Organizations. The snapshots must be copied to a central forensics account. Which combination of steps is MOST efficient?

⚠ Common exam trap

Many exam-takers choose DLM (Option A) because it is commonly used for snapshot automation, but they overlook that DLM cannot copy snapshots across accounts, which is a critical requirement for cross-account forensics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Backup to create backup plans in each account and enable cross-account backup copy to the forensics account.

AWS Backup is the most efficient solution because it natively supports cross-account backup copy, allowing you to create backup plans in each account and automatically copy EBS snapshots to a central forensics account without custom scripting or manual intervention. This integrates directly with AWS Organizations, enabling centralized management of backup policies across multiple accounts, which is ideal for incident response scenarios requiring rapid, consistent snapshot collection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Amazon Data Lifecycle Manager (DLM) to create snapshots and copy them to the forensics account using S3 cross-region replication.

    Why it's wrong here

    Amazon Data Lifecycle Manager can automate EBS snapshot creation, but it has no native cross-account copy destination; DLM policies operate within the source account and rely on manual snapshot sharing or custom automation to deliver copies to a forensics account. Additionally, S3 cross-region replication is irrelevant here because EBS snapshots are stored in the Amazon EBS snapshot service, not as S3 objects. This makes it an inflexible choice compared to AWS Backup's centralized cross-account copy.

  • ✗

    Use AWS CloudFormation StackSets to deploy a stack that creates snapshots and copies them manually.

    Why it's wrong here

    AWS CloudFormation StackSets is designed to roll out the same CloudFormation stacks across many accounts and regions; it is not a backup or snapshot orchestration tool. To create and copy snapshots, a template would need custom resources such as Lambda functions, state-machine steps, and robust error handling, effectively asking you to build a mini backup service that AWS Backup already provides. Since StackSets also lacks built-in scheduling, retention, and verification mechanisms, it is an indirect and brittle method for forensic collection.

  • ✗

    Use AWS Systems Manager Automation to run scripts in each account that create snapshots and copy them to the forensics account via Lambda.

    Why it's wrong here

    AWS Systems Manager Automation relies on the instances having the SSM Agent installed and appropriate IAM permissions to execute scripts, but it cannot natively orchestrate snapshot creation and cross-account copying across multiple AWS Organizations member accounts without additional cross-account roles and Lambda invocations, making it less direct than using AWS Backup with a centralised backup policy. This option is tempting because Systems Manager Automation is commonly used for operational runbooks and patching across accounts, and would be correct for tasks like applying a standard configuration or running a script on many instances simultaneously.

  • ✓

    Use AWS Backup to create backup plans in each account and enable cross-account backup copy to the forensics account.

    Why this is correct

    AWS Backup is the correct choice because it natively supports scheduled backup plans, retention management, and cross-account backup copy in a single service. By enabling the AWS Backup organization feature, you can centrally define backup plans and automatically apply them to resources across all accounts, with copies delivered to the forensics account. The service also handles encryption with KMS keys, monitoring with CloudWatch, and audit trails via CloudTrail, which is essential for a defensible forensic process.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.