SCS-C02 Threat Detection and Incident Response Practice Question
During an incident response, a security team needs to capture a memory dump of an Amazon EC2 instance running Linux. What is the recommended approach?
⚠ Common exam trap
Test-takers frequently confuse memory capture with disk capture, assuming an EBS snapshot or Inspector can retrieve volatile data, when in fact only a tool like LiME executed on the running instance can capture RAM.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS Systems Manager Run Command to run a script that extracts memory using LiME.
AWS Systems Manager Run Command allows you to execute a script on a running EC2 instance without needing SSH access, and LiME (Linux Memory Extractor) is a trusted tool for capturing volatile memory. This approach preserves the memory state for forensic analysis while maintaining the instance's running state, which is critical for incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use AWS Systems Manager Run Command to run a script that extracts memory using LiME.
Why this is correct
AWS Systems Manager Run Command is the correct approach because it can execute a script on the running EC2 instance through the SSM agent, installing the LiME kernel module and dumping the full contents of volatile memory to a file. The acquired memory image can then be uploaded to S3 for forensic analysis. Unlike other methods, Run Command works while the instance remains powered on, which is essential because memory is lost the moment the instance is stopped or rebooted. It also provides fine-grained IAM permissions and a complete audit trail of the command invocation.
- ✗
Use Amazon Inspector to collect memory dumps.
Why it's wrong here
Amazon Inspector is a vulnerability management service that performs agent-based and network-based assessments for software vulnerabilities, unintended network exposure, and compliance drift, not memory acquisition. It does not have any capability to read kernel memory, attach debuggers, or generate a raw memory dump file from a running instance. Running Inspector during an incident would only produce a list of security findings, not the volatile data needed for forensic analysis. Memory forensics requires a dedicated tool like LiME or a crash dump utility instead.
- ✗
Stop the instance and create an EBS snapshot for memory analysis.
Why it's wrong here
Stopping the instance and creating an EBS snapshot captures only the persistent disk volumes attached to the instance, such as the root volume, while the contents of RAM are wiped the instant the instance transitions to the stopped state. Since memory forensics requires examination of volatile data like running processes, kernel structures, and open network sockets, an EBS snapshot is useless for that purpose and can only support disk forensics. Furthermore, stopping an instance may trigger graceful shutdown routines that alter system state or tamper with evidence. The correct incident response is to acquire memory first, while the instance is still running.
- ✗
Use the EC2 console to take a screenshot and capture memory from the hypervisor.
Why it's wrong here
The EC2 console offers a screenshot feature that retrieves a bitmap of the display output from the instance's virtual console, which merely shows a static picture of the screen and contains none of the memory contents. There is no hypervisor-level API or console action that can dump guest RAM to a file, and AWS does not expose such functionality for security and isolation reasons. Any attempt to capture memory from the hypervisor layer would violate the shared responsibility model, since the guest's memory is customer data. Therefore, memory acquisition must be performed from inside the guest operating system using a tool like LiME.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.