GCFA Enterprise Environment Incident Response Practice Question
During a cloud-based incident, you determine that an attacker has gained access to an IAM role with excessive permissions. What is the most effective containment step to minimize the blast radius without causing immediate service outages?
⚠ Common exam trap
Candidates often choose to delete the entire IAM role or disable the root account, causing catastrophic service outages rather than applying targeted containment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach an inline policy to deny all actions for the compromised role.
In cloud environments, the most precise way to contain an identity-based attack is to apply an inline policy to the compromised role that explicitly denies all actions, or to revoke the active session tokens. By narrowing the scope of permissions or invalidating current credentials, responders can prevent the attacker from performing further unauthorized API calls while allowing legitimate, non-impacted services to continue functioning correctly within the environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the IAM role immediately.
Why it's wrong here
Deleting the IAM role is a destructive action that can cause immediate, widespread service outages for any legitimate resource currently using that role. This is an excessive containment measure that disrupts business operations and removes forensic evidence that may be needed to determine what the attacker actually accessed.
- ✓
Attach an inline policy to deny all actions for the compromised role.
Why this is correct
Attaching a 'Deny All' policy is the most effective way to neutralize the compromised role instantly. Because explicit denies always override allows in IAM, the attacker loses the ability to execute any commands, while the role itself remains in the cloud configuration for forensic investigation and audit purposes.
- ✗
Change the password for the root user account.
Why it's wrong here
The incident involves a compromised IAM role, not the root account. Changing the root password does not affect the permissions or active sessions of an IAM role. This action is irrelevant to the containment of the specific threat vector identified and fails to stop the attacker's unauthorized activity.
- ✗
Disable the entire cloud subscription or account.
Why it's wrong here
Disabling the entire account is a 'scorched earth' approach that stops all services, including production systems and customer-facing applications. This is rarely the right choice for an incident responder unless the threat is so severe that it threatens the entire infrastructure. It is inefficient and causes unnecessary business damage.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every GCFA question from scratch — 292 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.