Courseiva

SCS-C02 Threat Detection and Incident Response Practice Question

Which TWO steps are part of the forensic acquisition process for an EC2 instance suspected of being compromised?

⚠ Common exam trap

It's easy for candidates to confuse incident response containment (stopping or terminating the instance) with forensic acquisition, which requires preserving both volatile memory and disk state before any changes are made.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture the instance's memory using a forensic tool.

Capturing the instance's memory using a forensic tool (such as LiME or F-Response) preserves volatile data—including running processes, network connections, and encryption keys—that would be lost if the instance were stopped or terminated. This is a critical step in the forensic acquisition process to gather evidence of compromise without altering the system state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Stop the instance immediately to prevent further damage.

    Why it's wrong here

    Stopping the instance is not a forensic acquisition step because a graceful shutdown triggers the guest OS to run shutdown scripts that may delete or alter files, and all volatile memory (RAM) is lost the instant power is cut. In incident response, you want to capture evidence before taking any action that changes the system state. Stopping also does not preserve network connections or running processes for later analysis.

  • ✗

    Enable termination protection on the instance.

    Why it's wrong here

    Enabling termination protection is a preventive control meant to stop accidental termination, not a forensic acquisition method. It does not copy or capture any evidence from the instance, nor does it preserve volatile memory or disk state. This action changes the instance's attributes (the protection flag) but provides zero evidentiary value for forensic analysis.

  • ✗

    Terminate the instance to ensure the threat is contained.

    Why it's wrong here

    Terminating the instance is the opposite of forensic acquisition because it deletes the instance and its associated resources, erasing both the root EBS volume (unless snapshotting is done first) and any chance of memory capture. While it may contain the threat, it destroys the very evidence needed to determine the root cause and scope of compromise. Forensic best practice is to preserve, not destroy, the system under investigation.

  • ✓

    Capture the instance's memory using a forensic tool.

    Why this is correct

    Capturing memory using a forensic tool is a correct forensic acquisition step because RAM contains volatile data such as running processes, open network connections, loaded kernel modules, and decryption keys that are lost when power is removed. In AWS, memory capture must be performed on the live instance, typically using tools like LiME or a memory dump utility, before any shutdown or snapshot. This preserves the most ephemeral evidence first, following the order of volatility.

  • ✓

    Create a snapshot of the root EBS volume.

    Why this is correct

    Creating a snapshot of the root EBS volume is a correct forensic acquisition step because it captures the non-volatile disk state, including the operating system, user files, malware binaries, and logs. In AWS, you can snapshot the volume while the instance is running, but for a more consistent capture you should isolate the instance or use the crash-consistent snapshot approach. The snapshot provides a durable, point-in-time image that can be mounted on a separate analysis instance without altering the original evidence.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.