Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

During an incident response, a security engineer needs to collect volatile memory from a compromised EC2 instance without affecting the running system. The instance is critical and cannot be stopped. Which approach is most appropriate?

⚠ Common exam trap

Test-takers frequently think stopping the instance (Option A) is safe for forensics, but they forget that volatile memory is lost on shutdown, making it useless for memory analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS Systems Manager Run Command to execute a memory capture utility.

AWS Systems Manager Run Command allows you to execute a memory capture utility (such as WinPmem or LiME) on the EC2 instance without stopping it, preserving volatile memory for forensic analysis. This approach uses the SSM Agent to run commands remotely, minimizing impact on the running system while collecting critical evidence like running processes, network connections, and kernel data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stop the instance, detach the root volume, and attach it to a forensics instance for analysis.

    Why it's wrong here

    Stopping the instance is a state-changing operation that powers down the operating system, causing all volatile memory (RAM) to be lost before it can be acquired. Incident response memory forensics requires capturing the live memory contents, which contain running processes, network connections, and encryption keys; detaching and analyzing only the root volume provides disk evidence but never the volatile evidence. Additionally, an abrupt stop may alert an attacker who has established persistence or monitoring on the instance, and it violates the principle of preserving the original evidence state.

  • ✗

    Use AWS License Manager to create a snapshot of the instance memory.

    Why it's wrong here

    AWS License Manager is a service designed to track and control software license usage across your AWS environment; it has no integration with EC2 instance internals and cannot read or snapshot memory. Memory acquisition requires executing a utility inside the guest OS or using a hypervisor-level capability, neither of which License Manager provides. Therefore, using License Manager for memory capture is categorically incorrect and would produce no forensic data.

  • ✗

    Use Amazon EC2 Rescue to collect memory dump.

    Why it's wrong here

    Amazon EC2 Rescue is a command-line tool that automates OS-level troubleshooting by gathering system logs, configuration files, and performance data, but it does not perform full memory acquisition. Its purpose is to diagnose issues like boot failures or network misconfigurations, not to preserve volatile evidence. While EC2 Rescue runs on the instance and may capture some diagnostic outputs, it cannot dump the raw contents of physical memory for forensic analysis, so it would not satisfy the requirement for a memory dump.

  • ✓

    Use AWS Systems Manager Run Command to execute a memory capture utility.

    Why this is correct

    AWS Systems Manager Run Command offers a way to execute an approved memory capture utility (e.g., LiME, DumpIt, or a custom script) directly on the live instance without stopping it, preserving the volatile memory contents. Because the command runs in the guest OS via the SSM Agent, it can invoke kernel-level memory dumping tools with the appropriate privileges, and the captured image can be streamed to S3 for forensic analysis. This approach minimizes disruption and avoids alerting the attacker, making it the correct choice among the options.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.