Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which THREE steps should a security engineer take to ensure that an incident response plan for an AWS environment is effective? (Choose three.)

⚠ Common exam trap

The trap here is that candidates may mistakenly believe the root user is necessary for incident response due to its full permissions, but AWS best practices and the SCS-C02 exam emphasize using IAM roles with just-in-time access and MFA for all response actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regularly test the incident response plan through tabletop exercises and simulations.

Regularly testing the incident response plan through tabletop exercises and simulations validates the plan's effectiveness, identifies gaps, and ensures team readiness. AWS recommends using Game Days and fault injection simulators to practice real-world scenarios without impacting production environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Regularly test the incident response plan through tabletop exercises and simulations.

    Why this is correct

    Tabletop exercises and game days on AWS simulate realistic compromise scenarios (e.g., a compromised EC2 instance or leaked access key) so responders can validate runbooks, verify IAM escalation/containment steps, and identify gaps before a real event. AWS Well-Architected and Security Incident Response guides recommend periodic testing to improve procedural accuracy, tool effectiveness, and decision-making under stress. This is a core preparedness activity.

  • ✓

    Document and maintain an up-to-date list of incident response team members and their contact information.

    Why this is correct

    Maintaining a current, authoritative roster of incident responders, their primary/secondary contacts, escalation paths, and on-call rotations ensures the right personnel are reachable within minutes during an event. Integrating this list with AWS Systems Manager Incident Manager or a chat tool prevents reliance on stale information or tribal knowledge and supports audit-readiness. Rapid notification is a prerequisite for effective coordinated response.

  • ✗

    Use the AWS account root user for incident response actions to ensure full permissions.

    Why it's wrong here

    Root user credentials are shared, long-lived, and typically lack fine-grained audit attribution, making them an unsafe choice for routine response actions. If an attacker rotates the root keys or enables virtual MFA, you can lose account recovery access; root also cannot be scoped by IAM policies. Pre-provisioned break-glass IAM roles with MFA, short-lived credentials, and a managed policy grant the necessary permissions while preserving traceability.

  • ✗

    Store all evidence in an S3 bucket with public read access for easy sharing.

    Why it's wrong here

    Public read access on an evidence S3 bucket can leak host logs, disk snapshots, or memory dumps containing customer data or secrets, creating a secondary breach and ruining legal admissibility. Evidence must remain in a private bucket with S3 Block Public Access enabled, SSE-KMS encryption, versioning, and an Object Lock policy to maintain integrity and chain of custody. Sharing is done through presigned URLs or controlled replication to authorized accounts.

  • ✓

    Automate containment actions using AWS Lambda and AWS Systems Manager.

    Why this is correct

    Triggering AWS Systems Manager Automation documents or Lambda functions on GuardDuty/EventBridge findings lets you isolate EC2 instances, detach EBS volumes, or revoke keys automatically without human wait time. This reduces mean-time-to-containment, enforces consistent actions across accounts and Regions, and minimizes manual errors during stress. Make sure runbooks are tested and permissions locked down to the automation role.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.