Courseiva

GCFA Enterprise Environment Incident Response Practice Question

During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?

⚠ Common exam trap

Candidates often choose to delete the entire IAM role or disable the root account, causing catastrophic service outages rather than applying targeted containment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an inline policy to deny all actions for the compromised role.

In cloud environments, the most precise way to contain an identity-based attack is to apply an inline policy to the compromised role that explicitly denies all actions, or to revoke the active session tokens. By narrowing the scope of permissions or invalidating current credentials, responders can prevent the attacker from performing further unauthorized API calls while allowing legitimate, non-impacted services to continue functioning correctly within the environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the IAM role immediately.

    Why it's wrong here

    Deleting the IAM role is a destructive action that can cause immediate, widespread service outages for any legitimate resource currently using that role. This is an excessive containment measure that disrupts business operations and removes forensic evidence that may be needed to determine what the attacker actually accessed.

  • ✓

    Attach an inline policy to deny all actions for the compromised role.

    Why this is correct

    Attaching a 'Deny All' policy is the most effective way to neutralize the compromised role instantly. Because explicit denies always override allows in IAM, the attacker loses the ability to execute any commands, while the role itself remains in the cloud configuration for forensic investigation and audit purposes.

  • ✗

    Change the password for the root user account.

    Why it's wrong here

    The incident involves a compromised IAM role, not the root account. Changing the root password does not affect the permissions or active sessions of an IAM role. This action is irrelevant to the containment of the specific threat vector identified and fails to stop the attacker's unauthorized activity.

  • ✗

    Disable the entire cloud subscription or account.

    Why it's wrong here

    Disabling the entire account is a 'scorched earth' approach that stops all services, including production systems and customer-facing applications. This is rarely the right choice for an incident responder unless the threat is so severe that it threatens the entire infrastructure. It is inefficient and causes unnecessary business damage.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.