Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which TWO actions should a security engineer take to investigate a potential AWS API credential leak? (Choose two.)

⚠ Common exam trap

It's easy for candidates to confuse 'rotating the keys' with 'changing the password' (Option B), not realizing that access keys and passwords are independent credentials, and that immediate rotation (Option D) is the correct containment action alongside forensic investigation (Option A).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS CloudTrail to review API calls made with the compromised keys.

AWS CloudTrail logs all API calls made within an AWS account, including those using compromised access keys. By reviewing these logs, a security engineer can identify the scope of the breach, such as which resources were accessed, from which IP addresses, and at what times. This is a critical first step in incident response to understand the impact and gather forensic evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS CloudTrail to review API calls made with the compromised keys.

    Why this is correct

    AWS CloudTrail is the authoritative audit service that records API calls made in your account, including the exact access key ID that signed each request. By querying CloudTrail events with the compromised access key ID, a security engineer can reconstruct the attacker's actions, identify which AWS resources were accessed or modified, and determine the scope of potential data exposure. This read-only forensic step does not alter the environment and should be performed immediately to capture evidence while the trail is still available.

  • ✗

    Change the IAM user's password.

    Why it's wrong here

    An IAM user's password controls access to the AWS Management Console, whereas programmatic access relies on access key pairs. Rotating or resetting the password has no effect on the validity of the leaked access keys, so the compromised programmatic credentials would remain active and usable. This action is only relevant if the user also used the console and you suspect the password was compromised, but it does not address the access key incident.

  • ✗

    Disable all AWS services in the account.

    Why it's wrong here

    Disabling all AWS services in the account is a disproportionate response that would cause a service outage across every workload and potentially destroy ephemeral resources that could serve as forensic evidence. It also fails to target the actual compromise vector, leaving the leaked access keys valid but the account unable to operate. A proper incident response should contain the specific IAM principal by rotating its keys and using an explicit deny policy, not halt the entire AWS environment.

  • ✓

    Immediately rotate the compromised access keys.

    Why this is correct

    Rotating the compromised access keys means deactivating the existing active keys and issuing new ones for the IAM user, which immediately invalidates the leaked credentials and stops ongoing unauthorized access. This is a critical containment action because the old keys can be used to make authenticated API calls until they are rotated or deleted. The rotation event itself is recorded by CloudTrail, preserving the audit trail and allowing you to correlate activity before and after the rotation.

  • ✗

    Delete the IAM user and recreate it with the same permissions.

    Why it's wrong here

    Deleting the IAM user is counterproductive because it removes the user's unique ARN and the historical association between the compromised access keys and the API calls they made, severely impairing forensic analysis. Recreating the user with the same permissions would generate a new key pair, but you would lose the original user identity, any attached policies and group memberships would need to be re-applied, and any service-linked roles or resource permissions referencing that user would break. Rotating the keys is the safer option because it preserves the user entity and its audit history.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.