Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

An incident response playbook for a cloud environment includes containment steps. For a compromised IAM user in AWS, which action is least likely to be effective for containment?

⚠ Common exam trap

The misconception that changing a password is a universal containment action is common, but in cloud environments with multiple credential types (access keys, STS tokens), password changes alone are insufficient to stop ongoing abuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change the IAM user's password

Changing the IAM user's password does not invalidate existing authenticated sessions or tokens (such as temporary credentials from STS or access keys). An attacker who has already established a session or obtained access keys can continue to use them until they expire or are explicitly revoked. Therefore, password change alone is ineffective for immediate containment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the IAM user

    Why it's wrong here

    Disabling the IAM user immediately revokes its credentials, blocking further API calls, so it is an effective containment step. It is tempting to dismiss because disabling is reversible and leaves resources intact, but that reversibility is exactly why it is preferred over deletion during containment; the question asks for the least effective action.

  • ✓

    Change the IAM user's password

    Why this is correct

    Changing the password does not revoke existing credentials. An attacker holding active access keys or session tokens continues operating, so this containment step fails. Deactivating the user, deleting access keys and revoking sessions are required to actually cut off access.

  • ✗

    Attach a DenyAll policy to the user

    Why it's wrong here

    An explicit DenyAll policy blocks API actions but does not invalidate existing temporary credentials or console sessions, and it can be reverted by anyone with IAM permissions. It is tempting because policy-based denial is the usual least-privilege mechanism, and it would be correct for restricting a user's future permissions rather than containing an active compromise.

  • ✗

    Disable the IAM user's access keys

    Why it's wrong here

    Disabling access keys only blocks programmatic API calls; the compromised user's console password and active sessions remain valid, so an attacker keeps access. It is tempting because key rotation is standard hygiene, and disabling keys is the right containment step when the compromise is confirmed to be limited to programmatic access.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.