Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Exhibit

2023-01-15T10:30:00Z 123456789012 ENI eni-0a1b2c3d4e5f67890 192.0.2.10 203.0.113.50 443 80 6 10 1000 1500 ACCEPT OK

Refer to the exhibit. A security engineer is analyzing a VPC Flow Logs entry for an EC2 instance with private IP 192.0.2.10. The log shows an accepted outbound connection from the instance to 203.0.113.50 on port 443. The instance is not expected to initiate outbound HTTPS connections. What should the engineer do next to investigate?

⚠ Common exam trap

Many exam-takers assume the first step is to modify network controls (security groups or DNS logs) rather than performing host-level investigation, which is the correct incident response priority when the instance itself is the source of unexpected traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log into the instance and check for unauthorized processes or malware.

The VPC Flow Logs show an accepted outbound connection from the EC2 instance to an external IP on port 443, which is unexpected behavior. The immediate next step is to log into the instance and investigate for unauthorized processes, malware, or compromised credentials that could be initiating this outbound HTTPS traffic. This aligns with incident response best practices: verify the host before making network-level changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Log into the instance and check for unauthorized processes or malware.

    Why this is correct

    The observed egress traffic to a suspicious external IP is an indicator, but the only way to determine whether the instance is actually compromised is to inspect the operating system itself. Using a secure channel such as AWS Systems Manager Session Manager, you can examine running processes, active network sockets, scheduled tasks, and persistence mechanisms for malware, crypto miners, or reverse shells. This host-level triage is the correct immediate next step because it directly establishes the root cause and preserves forensic evidence before taking any broader network or DNS-based action.

  • ✗

    Block the IP 203.0.113.50 in the security group immediately.

    Why it's wrong here

    Immediately adding a deny rule for 203.0.113.50 is counterproductive because it can alert the adversary to your response, giving them time to wipe evidence, change their command-and-control endpoint, or move laterally. It also treats only a single artifact of the attack while ignoring the possibility that the instance has already been compromised and may be sending data elsewhere. The correct first move is to preserve the evidence by isolating the host rather than modifying security group rules, because a security group change does not terminate an already-established connection or stop an attacker who can pivot to another IP.

  • ✗

    Check the security group rules to see if outbound HTTPS is allowed.

    Why it's wrong here

    Because the flow logs already show outbound HTTPS connections being accepted, the security group must already be allowing that traffic, so re-reading the rules would only confirm a configuration fact that is evident from the observed connection. Security groups are stateful and apply only to new connections; they do not inspect the content of the traffic, so an allowed rule does not reveal whether that traffic is legitimate or malicious. Checking the security group rule gives no visibility into which process on the instance opened the connection, so it cannot be the correct next step for determining whether the host is compromised.

  • ✗

    Check Amazon Route 53 DNS logs to see what domain was resolved.

    Why it's wrong here

    Route 53 resolver query logs could later help identify the domain that was resolved and support a broader indicator-of-compromise investigation, but they are not the immediate priority because DNS logs show only name-resolution requests, not the process, binary, or memory state responsible for the outbound connection. DNS logs may also be disabled or incomplete, and an attacker can easily bypass them by using a direct IP address or DNS-over-HTTPS. The direct path to confirming and containing the intrusion is to investigate the instance itself; DNS log analysis should follow after you have identified the compromised host.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.