Courseiva
mediumMultiple Choice

SSCP A company uses AWS for critical workloads Practice Question

A company uses AWS for critical workloads. An analyst notices unauthorized API calls from an IP address outside the company. The logs show that the attacker used stolen access keys belonging to an IAM user with administrative privileges. The incident response team must contain the breach as quickly as possible. The analyst has access to the AWS Management Console and can use the CLI. The team is following the incident response plan. Which action should be taken FIRST to prevent further unauthorized actions?

⚠ Common exam trap

ISC2 often tests the principle of least disruption during containment — candidates may choose to delete the user or block the IP, but the correct first step is to disable the specific compromised credential to stop the attack without breaking other dependencies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Disable the compromised access keys using the IAM dashboard or CLI.

The immediate priority in an access key compromise is to invalidate the stolen credentials to stop the attacker from making further API calls. Disabling the compromised access keys via the IAM dashboard or CLI (using `aws iam update-access-key --status Inactive`) is the fastest containment action that directly revokes the attacker's authentication token without disrupting other legitimate users or services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new security group to block the attacker's source IP at the network level.

    Why it's wrong here

    A security group only filters traffic at the resource level and cannot stop an IAM principal with administrative privileges from calling AWS APIs directly. It is tempting because network blocking feels immediate, but the compromised access keys must be deactivated first, since the attacker's calls do not originate from resources governed by that security group.

  • ✓

    Disable the compromised access keys using the IAM dashboard or CLI.

    Why this is correct

    Disabling the compromised access keys immediately invalidates the stolen credentials, halting the attacker's unauthorised API calls. This contains the breach fastest, satisfying the stem's priority, whereas deleting the IAM user or reviewing logs leaves the active keys usable in the interim.

  • ✗

    Delete the compromised IAM user immediately.

    Why it's wrong here

    Deleting the IAM user removes the identity but leaves the stolen access keys valid until deletion completes, and destroys audit evidence needed for investigation. It is tempting as a decisive containment step, yet deactivating the user and its keys is the correct first action, preserving forensic data while immediately halting API calls.

  • ✗

    Rotate all IAM user access keys across the entire AWS account.

    Why it's wrong here

    Rotating every IAM user's keys across the account is broad and slow, disrupting legitimate users while the attacker's stolen keys may remain active during the process. It is tempting as thorough remediation, but deactivating the specific compromised user's access keys first stops the unauthorised API calls immediately, with account-wide rotation performed afterwards.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.