CS0-003 Security Operations Practice Question
A cloud security analyst reviews AWS CloudTrail logs and notices multiple 'RunInstances' API calls from a single IAM user creating EC2 instances with public IP addresses in an unusual region. What is the most likely concern?
⚠ Common exam trap
CS0-004 often tests whether candidates can distinguish a genuine security incident (compromised credentials, cryptomining) from benign operational explanations (scaling, new projects) by focusing on anomalies like unusual region and public IP exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user's credentials may be compromised and used for cryptomining
Multiple RunInstances calls from a single IAM user creating public-IP EC2 instances in an unusual region is a textbook indicator of compromised credentials being used for cryptomining. Attackers favor this pattern because it rapidly provisions compute resources for mining, often in regions the victim doesn't normally use to evade detection and quota monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user's credentials may be compromised and used for cryptomining
Why this is correct
When threat actors compromise AWS IAM credentials, they frequently target unused geographical regions to evade detection while spinning up high-performance EC2 instances for illicit cryptocurrency mining. This anomalous behavior is flagged in CloudTrail logs by API calls like RunInstances originating from unfamiliar IPs and targeting non-standard regions, which deviates sharply from established baseline activity.
- ✗
The user is performing legitimate scaling operations
Why it's wrong here
Legitimate scaling operations in AWS are typically managed programmatically through Auto Scaling groups or infrastructure-as-code tools rather than manual, ad-hoc API calls. Furthermore, these automated scaling events occur within pre-defined, active production regions and VPCs, rather than suddenly provisioning public-facing resources in completely unused geographical regions.
- ✗
The user is provisioning resources for a new project
Why it's wrong here
Although organizations occasionally spin up resources for new initiatives, standard enterprise governance dictates that new projects undergo formal change management and deploy within approved, architected landing zones. The sudden, uncoordinated creation of instances with public IP addresses in an unapproved region strongly indicates a security incident rather than authorized development activity.
- ✗
The user is testing disaster recovery procedures
Why it's wrong here
Disaster recovery exercises are highly structured, scheduled events that utilize pre-configured templates, replication tools like AWS Elastic Disaster Recovery, and designated target DR regions. Unplanned, manual resource creation in random or cheap compute regions does not align with documented DR runbooks or business continuity testing protocols.
Go deeper
Related to this question
Learn chapter
Infrastructure-as-Code Security Scanning
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.