A security analyst is investigating a suspected compromise of an AWS environment. The analyst discovers that an IAM user's access key was used from an unknown IP address to enumerate S3 buckets and download objects. The analyst needs to secure the environment and gather evidence. Which TWO actions should the analyst take to both contain the incident and preserve forensic data? (Choose two.)
Deactivating the access key immediately prevents further use of the stolen credentials, stopping the attacker from continuing to access AWS resources. It does not delete the key, so it can be re-enabled if needed for legitimate purposes, and it preserves the key's metadata for audit. This is a critical containment step that balances security with the need to maintain evidence.
Why this answer
Deactivating the compromised access key immediately stops the attacker from using it, while reviewing CloudTrail logs provides the necessary forensic evidence to understand the extent of the breach. Together, these actions contain the incident without destroying evidence. Deleting the user, enabling new logging, or rotating all keys either destroy evidence, fail to address the active threat, or cause unnecessary disruption.
Exam trap
The trap here is thinking that deleting the compromised IAM user is the best containment step; however, deletion destroys audit trails and can break legitimate access, whereas deactivation preserves evidence and is reversible.