Courseiva
Cloud Security Operations →mediumMultiple Select

CCSP Cloud Security Operations Practice Question

A cloud security team is building an incident response runbook for workloads on AWS. They need to ensure that when a compromised EC2 instance is detected, responders can preserve volatile evidence and prevent further malicious activity without destroying forensic artifacts. (Choose two.)

⚠ Common exam trap

The trap here is prioritizing immediate eradication, terminating or rebooting the instance, over containment and evidence preservation, which destroys volatile artifacts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture an EBS snapshot of the instance's volumes before making changes.

Effective cloud incident response follows the order of containment and preservation before remediation. Isolating the instance with a restrictive security group stops command-and-control and lateral movement while keeping the system alive, and capturing EBS snapshots first preserves disk artifacts. Together these steps contain the threat without destroying the evidence responders need.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reboot the instance to clear any malicious processes from memory.

    Why it's wrong here

    A reboot wipes volatile memory, destroying indicators such as injected code and in-memory credentials that investigators need. It also may trigger attacker persistence mechanisms on startup, so it is counterproductive when the goal is evidence preservation and containment.

  • ✓

    Capture an EBS snapshot of the instance's volumes before making changes.

    Why this is correct

    An EBS snapshot captures the block-level state of the attached volumes, preserving disk-based artifacts such as logs, binaries, and configuration. Taking it before remediation ensures the evidence remains intact even if the instance is later terminated or modified, which is essential for forensic analysis and legal defensibility.

  • ✓

    Isolate the instance using a security group that allows no inbound or outbound traffic.

    Why this is correct

    Replacing the instance's security groups with a restrictive isolation group blocks command-and-control and lateral movement while keeping the instance running for memory capture and live analysis. This contains the threat without destroying volatile evidence, which is the recommended containment step.

  • ✗

    Terminate the instance immediately to stop the attacker.

    Why it's wrong here

    Termination destroys the running state, including memory contents and any unflushed data, and may also delete ephemeral storage. It is a destructive action that eliminates evidence, so it should not be the first step in an investigation where artifacts must be preserved.

  • ✗

    Detach the root volume and attach it to an analysis instance without snapshotting first.

    Why it's wrong here

    Detaching the root volume from a running instance is not a supported operation and would disrupt the instance; more importantly, performing it without a snapshot risks altering or losing evidence. The snapshot should be taken first, then the volume can be examined from a controlled forensic workstation.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.