CCSP Cloud Security Operations Practice Question
An incident response playbook for a cloud environment includes containment steps. For a compromised IAM user in AWS, which action is least likely to be effective for containment?
⚠ Common exam trap
The misconception that changing a password is a universal containment action is common, but in cloud environments with multiple credential types (access keys, STS tokens), password changes alone are insufficient to stop ongoing abuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the IAM user's password
Changing the IAM user's password does not invalidate existing authenticated sessions or tokens (such as temporary credentials from STS or access keys). An attacker who has already established a session or obtained access keys can continue to use them until they expire or are explicitly revoked. Therefore, password change alone is ineffective for immediate containment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the IAM user
Why it's wrong here
Disabling the IAM user immediately revokes its credentials, blocking further API calls, so it is an effective containment step. It is tempting to dismiss because disabling is reversible and leaves resources intact, but that reversibility is exactly why it is preferred over deletion during containment; the question asks for the least effective action.
- ✓
Change the IAM user's password
Why this is correct
Changing the password does not revoke existing credentials. An attacker holding active access keys or session tokens continues operating, so this containment step fails. Deactivating the user, deleting access keys and revoking sessions are required to actually cut off access.
- ✗
Attach a DenyAll policy to the user
Why it's wrong here
An explicit DenyAll policy blocks API actions but does not invalidate existing temporary credentials or console sessions, and it can be reverted by anyone with IAM permissions. It is tempting because policy-based denial is the usual least-privilege mechanism, and it would be correct for restricting a user's future permissions rather than containing an active compromise.
- ✗
Disable the IAM user's access keys
Why it's wrong here
Disabling access keys only blocks programmatic API calls; the compromised user's console password and active sessions remain valid, so an attacker keeps access. It is tempting because key rotation is standard hygiene, and disabling keys is the right containment step when the compromise is confirmed to be limited to programmatic access.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.