Courseiva

GCIH Securing Credentials and Data in Cloud Practice Question

During a cloud incident response engagement, an analyst reviews AWS CloudTrail logs and finds that an access key belonging to an IAM user was used from an unfamiliar IP address to call GetSecretValue against AWS Secrets Manager. The key is still active. Which immediate containment action best limits further credential misuse while preserving the ability to investigate who used the key?

⚠ Common exam trap

The trap here is assuming that restricting the key by source IP or waiting for a detection service to flag the behavior constitutes containment, when the exposed credential itself must be deactivated to stop misuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deactivate the access key with UpdateAccessKey, then rotate the key and review CloudTrail history associated with that key ID.

The exposed long-term access key is the active threat, so the priority is to make it unusable right away. Deactivating the key with UpdateAccessKey halts all API calls tied to that credential while leaving the IAM user and its policies intact for analysis. CloudTrail retains the access key ID in every event record, so the investigation can continue after containment. Rotating the credential afterward restores access without reintroducing the compromised secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AWS GuardDuty and wait for its findings to confirm the anomaly before taking any action on the credential.

    Why it's wrong here

    GuardDuty is a detection service that analyzes CloudTrail, VPC Flow Logs, and DNS logs to surface findings, but enabling it does not revoke the leaked key. Waiting for detection delays containment while the attacker continues to call GetSecretValue and potentially other APIs. Detection tooling complements containment; it does not replace the immediate need to invalidate the exposed credential once misuse is confirmed.

  • ✗

    Delete the IAM user entirely with DeleteUser and recreate it later with the same permissions and a new access key.

    Why it's wrong here

    Deleting the IAM user removes the identity, its policies, group memberships, and any attached metadata, which can disrupt legitimate workloads and complicate attribution during the investigation. CloudTrail events for the deleted user still exist, but correlating them to a rebuilt user is messier. Deactivation is reversible and targeted, whereas deletion is a destructive, harder-to-undo action that exceeds what containment requires.

  • ✗

    Attach an inline IAM policy to the user that denies all actions with a Condition testing aws:SourceIp against the unfamiliar address.

    Why it's wrong here

    A deny-by-source-IP policy only blocks calls from that one address; the attacker can simply route through a different IP, a VPN, or a cloud proxy and the key keeps working. It also leaves the exposed access key active, so the credential remains usable from anywhere the attacker chooses next. This slows the attacker briefly but does not contain the compromised credential itself.

  • ✓

    Deactivate the access key with UpdateAccessKey, then rotate the key and review CloudTrail history associated with that key ID.

    Why this is correct

    Deactivating the access key immediately stops any further API calls using that credential, which is the fastest containment step for a leaked long-term key. Because CloudTrail records the access key ID on every event, the history for that key remains queryable after deactivation, so the analyst can still reconstruct what the attacker did. Rotating afterward restores legitimate access safely.

About these practice questions

This GCIH question is part of Courseiva's 322-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCIH practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCIH exam.