Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

A security analyst is investigating a suspected compromise of an AWS environment. The analyst discovers that an IAM user's access key was used from an unknown IP address to enumerate S3 buckets and download objects. The analyst needs to secure the environment and gather evidence. Which TWO actions should the analyst take to both contain the incident and preserve forensic data? (Choose two.)

⚠ Common exam trap

The trap here is thinking that deleting the compromised IAM user is the best containment step; however, deletion destroys audit trails and can break legitimate access, whereas deactivation preserves evidence and is reversible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deactivate the compromised access key.

Deactivating the compromised access key immediately stops the attacker from using it, while reviewing CloudTrail logs provides the necessary forensic evidence to understand the extent of the breach. Together, these actions contain the incident without destroying evidence. Deleting the user, enabling new logging, or rotating all keys either destroy evidence, fail to address the active threat, or cause unnecessary disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deactivate the compromised access key.

    Why this is correct

    Deactivating the access key immediately prevents further use of the stolen credentials, stopping the attacker from continuing to access AWS resources. It does not delete the key, so it can be re-enabled if needed for legitimate purposes, and it preserves the key's metadata for audit. This is a critical containment step that balances security with the need to maintain evidence.

  • ✗

    Rotate all IAM user access keys in the account.

    Why it's wrong here

    Rotating all access keys is a drastic measure that can disrupt many users and services, and it does not directly address the compromised key if it remains active. It also generates new credentials that may not be properly secured, potentially introducing new risks. A targeted response to the compromised key is more appropriate and less disruptive.

  • ✓

    Review AWS CloudTrail logs for the compromised access key.

    Why this is correct

    Reviewing CloudTrail logs allows the analyst to identify all actions performed with the compromised key, including the source IP, time, and affected resources. This is essential for understanding the scope of the breach and preserving evidence. It does not stop the attack but is a necessary investigative step that complements containment.

  • ✗

    Enable AWS CloudTrail logging for all regions.

    Why it's wrong here

    While enabling CloudTrail is a best practice for ongoing monitoring, it does not retroactively capture past events and does not help contain an active incident. If CloudTrail was not already enabled, historical API activity may be lost. For the current incident, the analyst needs to act on existing logs and stop the attack, not just enable future logging.

  • ✗

    Delete the IAM user associated with the access key.

    Why it's wrong here

    Deleting the IAM user removes all associated policies and access keys, which can disrupt legitimate operations and destroy valuable forensic evidence such as the user's permissions history and access patterns. It is an irreversible action that may hinder the investigation. Deactivation of the access key is a more measured response that achieves containment without losing data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every GCIH question from scratch — 322 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.