SCS-C02 Threat Detection and Incident Response Practice Question
Which TWO steps should a security engineer take when responding to a confirmed security incident involving a compromised EC2 instance? (Choose 2.)
⚠ Common exam trap
Many exam-takers confuse 'immediate termination' (Option E) with containment, but AWS incident response frameworks emphasize preserving evidence and isolating rather than destroying the instance, as termination eliminates the ability to perform memory forensics and root cause analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the instance by changing its security group to deny all traffic
Option C is correct because isolating the compromised EC2 instance by replacing its security group with one that denies all inbound and outbound traffic is the standard containment step that stops lateral movement and command-and-control communication while preserving the instance's volatile state for investigation. Option D is correct because taking EBS snapshots of the instance's volumes captures a point-in-time, read-only copy of the disk that can be mounted on a separate forensic workstation for evidence preservation and analysis without altering the original data. Option A is not appropriate as a first response because reimaging destroys volatile evidence and should only occur after containment and forensic capture are complete. Option B is wrong because deleting CloudTrail logs is log tampering that destroys the audit trail needed for the investigation. Option E is wrong because terminating the instance shuts it down and can destroy volatile memory and instance-store data before evidence is collected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reimage the instance from a clean AMI immediately
Why it's wrong here
Reimaging destroys volatile evidence such as memory-resident malware and running processes before forensic capture, and the compromised instance may still be needed for analysis. It is tempting because rebuilding from a trusted AMI is the standard remediation step once evidence has been preserved and the root cause identified.
- ✗
Delete all CloudTrail logs related to the instance
Why it's wrong here
Deleting CloudTrail logs destroys the audit trail required to establish the incident's timeline, scope and API activity, and may breach retention obligations. It is tempting because removing attacker-visible logging feels like containment, but log preservation is a core response step; deletion belongs only after lawful retention periods expire.
- ✓
Isolate the instance by changing its security group to deny all traffic
Why this is correct
Replacing the instance's security group with one that denies all inbound and outbound traffic severs command-and-control and exfiltration channels while preserving the instance's memory and disk state for investigation, satisfying containment without terminating evidence needed for the incident response.
- ✓
Take a snapshot of the instance's EBS volumes for forensic analysis
Why this is correct
Snapshotting the EBS volumes captures the compromised instance's disk state, including malware, logs and persistence artefacts, before remediation destroys it. This satisfies the forensic preservation requirement, enabling offline analysis while the isolated instance remains available for memory capture.
- ✗
Immediately terminate the instance to stop the attack
Why it's wrong here
Termination erases the instance's memory, disk and network state, destroying the forensic artefacts investigators need to determine scope and root cause. It is tempting because terminating an instance is a fast, decisive way to halt active attacker activity, and is valid once evidence has been captured and contained.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.