CCSP Cloud Security Operations Practice Question
A cloud security team is building an incident response runbook for workloads on AWS. They need to ensure that when a compromised EC2 instance is detected, responders can preserve volatile evidence and prevent further malicious activity without destroying forensic artifacts. (Choose two.)
⚠ Common exam trap
The trap here is prioritizing immediate eradication, terminating or rebooting the instance, over containment and evidence preservation, which destroys volatile artifacts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture an EBS snapshot of the instance's volumes before making changes.
Effective cloud incident response follows the order of containment and preservation before remediation. Isolating the instance with a restrictive security group stops command-and-control and lateral movement while keeping the system alive, and capturing EBS snapshots first preserves disk artifacts. Together these steps contain the threat without destroying the evidence responders need.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reboot the instance to clear any malicious processes from memory.
Why it's wrong here
A reboot wipes volatile memory, destroying indicators such as injected code and in-memory credentials that investigators need. It also may trigger attacker persistence mechanisms on startup, so it is counterproductive when the goal is evidence preservation and containment.
- ✓
Capture an EBS snapshot of the instance's volumes before making changes.
Why this is correct
An EBS snapshot captures the block-level state of the attached volumes, preserving disk-based artifacts such as logs, binaries, and configuration. Taking it before remediation ensures the evidence remains intact even if the instance is later terminated or modified, which is essential for forensic analysis and legal defensibility.
- ✓
Isolate the instance using a security group that allows no inbound or outbound traffic.
Why this is correct
Replacing the instance's security groups with a restrictive isolation group blocks command-and-control and lateral movement while keeping the instance running for memory capture and live analysis. This contains the threat without destroying volatile evidence, which is the recommended containment step.
- ✗
Terminate the instance immediately to stop the attacker.
Why it's wrong here
Termination destroys the running state, including memory contents and any unflushed data, and may also delete ephemeral storage. It is a destructive action that eliminates evidence, so it should not be the first step in an investigation where artifacts must be preserved.
- ✗
Detach the root volume and attach it to an analysis instance without snapshotting first.
Why it's wrong here
Detaching the root volume from a running instance is not a supported operation and would disrupt the instance; more importantly, performing it without a snapshot risks altering or losing evidence. The snapshot should be taken first, then the volume can be examined from a controlled forensic workstation.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.