Skip to content
BytePatterns

SCS-C03 · Domain 2: Incident Response · 14% of the exam

Task 2.1: Design and test an incident response plan

Being ready before it happens: runbooks and playbooks, access and tools provisioned in advance, a small blast radius, Shield Advanced protections, rehearsals with Fault Injection Service and Resilience Hub, and remediation that runs on its own through Systems Manager, Step Functions and Lambda.

Study it

  • Response plans and runbooks: Systems Manager OpsCenter and Automation

    Lesson coming

  • Prepared in advance: access, tools, blast radius and Shield Advanced

    Lesson coming

  • Testing the plan: Fault Injection Service and Resilience Hub

    Lesson coming

  • Automatic remediation: EventBridge, Step Functions, Lambda and Systems Manager

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 3

A company with Enterprise Support protects its CloudFront distributions and Application Load Balancers with AWS Shield Advanced. Before the next peak season it wants two things in place: the Shield Response Team (SRT) must be able to review AWS WAF logs and apply mitigations in the account during an attack, and the SRT must contact the company's on-call team directly when an attack affects the health of a protected application. Which steps should the company take? (Choose THREE.)

  1. AAuthorize the SRT with a role that has the AWSShieldDRTAccessPolicy managed policy
  2. BGrant the SRT access to the S3 bucket that stores the AWS WAF web ACL logs
  3. CSubscribe the distributions and load balancers to AWS Shield Standard protection
  4. DAssociate an Amazon Route 53 health check with each protected resource
  5. ECreate an AWS Firewall Manager Shield Advanced policy that covers the account
  6. FTurn on proactive engagement and enter the on-call contacts
Show the answer and why
  • AAuthorize the SRT with a role that has the AWSShieldDRTAccessPolicy managed policy

    Correct

    This role lets the SRT make Shield Advanced and AWS WAF API calls on the company's behalf and read its AWS WAF logs.

  • BGrant the SRT access to the S3 bucket that stores the AWS WAF web ACL logs

    Incorrect

    Not needed: the SRT gains access to AWS WAF web ACL logs with the account access. Bucket access is only for other data, such as load balancer logs.

  • CSubscribe the distributions and load balancers to AWS Shield Standard protection

    Incorrect

    Shield Standard protects all AWS customers automatically at no extra charge; there is nothing to subscribe to, and it adds no SRT support.

  • DAssociate an Amazon Route 53 health check with each protected resource

    Correct

    Proactive engagement is available only for protections that have an associated health check; the SRT uses its status to decide whether to engage.

  • ECreate an AWS Firewall Manager Shield Advanced policy that covers the account

    Incorrect

    Firewall Manager applies Shield Advanced protections across accounts and resources. It neither authorizes the SRT nor sets up proactive engagement.

  • FTurn on proactive engagement and enter the on-call contacts

    Correct

    With proactive engagement, the SRT contacts the people listed when a protected resource's availability is affected.

SRT help has two separate switches: account access through the DRT role, and proactive engagement, which depends on health checks and contacts. Both require Business or Enterprise Support.

Question 2 · choose 1

A team built an Amazon EventBridge rule that starts an isolation workflow when GuardDuty reports certain EC2 finding types. Before relying on it, the team must show that GuardDuty findings of those types actually match the rule and that the workflow runs end to end, without attacking its own instances. What should the team do?

  1. ARun an AWS Fault Injection Service experiment that stops instances in the target account
  2. BTest the event pattern in the EventBridge sandbox with a sample GuardDuty event
  3. CGenerate sample findings of those types with the CreateSampleFindings API
  4. DRun an AWS Resilience Hub assessment of the application and its resources
Show the answer and why
  • ARun an AWS Fault Injection Service experiment that stops instances in the target account

    Incorrect

    FIS runs fault injection experiments, such as stopping instances, to see how a workload behaves under faults. It is not a way to produce GuardDuty findings.

  • BTest the event pattern in the EventBridge sandbox with a sample GuardDuty event

    Incorrect

    The sandbox confirms that a sample event matches a pattern without a rule, but it does not run the rule's targets, so the workflow is never exercised.

  • CGenerate sample findings of those types with the CreateSampleFindings API

    Correct

    Sample findings use placeholder values and are meant for testing EventBridge rules and automation that act on findings.

  • DRun an AWS Resilience Hub assessment of the application and its resources

    Incorrect

    Resilience Hub assesses an application's resilience posture against its goals. It is not a source of GuardDuty findings.

To test a finding-driven response end to end, make GuardDuty emit a finding: sample findings carry "sample": true and a [SAMPLE] title, so the workflow should be able to recognize them.

Question 3 · choose 1

When GuardDuty reports certain EC2 findings, the security team wants an automatic response that captures memory, snapshots the volumes, replaces the security groups and notifies the on-call engineer. The steps must run in order with retries, and every run must keep a visual execution history for the audit. Which design meets these requirements?

  1. AAn AWS Config remediation action that runs a Systems Manager Automation document
  2. BA Security Hub CSPM automation rule that matches the finding types
  3. CAn OpsCenter OpsItem for each finding, from which responders run runbooks
  4. DAn EventBridge rule that starts an AWS Step Functions state machine
Show the answer and why
  • AAn AWS Config remediation action that runs a Systems Manager Automation document

    Incorrect

    Config remediation acts on resources that Config rules evaluate as noncompliant. It is not started by GuardDuty findings.

  • BA Security Hub CSPM automation rule that matches the finding types

    Incorrect

    Automation rules only update finding fields such as severity, notes and workflow status. They do not act on resources.

  • CAn OpsCenter OpsItem for each finding, from which responders run runbooks

    Incorrect

    OpsCenter helps people investigate and run runbooks, but each run is started by a person, so the response is not automatic.

  • DAn EventBridge rule that starts an AWS Step Functions state machine

    Correct

    A Standard workflow runs each step as a state, can retry failed steps, and keeps execution history with visual debugging.

Ordered steps, retries and an auditable run history describe an orchestrated workflow. The Automated Forensics Orchestrator for Amazon EC2 uses the same pattern: findings start Step Functions workflows.

Question 4 · choose 1

A security operations team wants each high-severity Security Hub CSPM finding to become a tracked work item that shows the affected resource, related items and its history, and from which responders can run approved Systems Manager Automation runbooks. Which service should the team use?

  1. ASecurity Hub CSPM custom insights
  2. BAWS Systems Manager OpsCenter
  3. CAmazon Detective finding groups
  4. DAmazon SNS email notifications from an EventBridge rule
Show the answer and why
  • ASecurity Hub CSPM custom insights

    Incorrect

    Insights group findings for review. They are not work items with status and do not run runbooks.

  • BAWS Systems Manager OpsCenter

    Correct

    OpsCenter turns events, including Security Hub CSPM findings, into OpsItems with resource context and related items, and offers Automation runbooks to resolve them.

  • CAmazon Detective finding groups

    Incorrect

    Finding groups help investigate related findings and entities. They do not track work or run Systems Manager runbooks.

  • DAmazon SNS email notifications from an EventBridge rule

    Incorrect

    Email tells people about a finding, but it gives no tracked item and no way to run a runbook from it.

A runbook-driven response plan needs somewhere to track each issue and launch the fix; in Systems Manager that place is OpsCenter.

Question 5 · choose 1

AWS sends security notices for an account to the root user's email address, which belongs to the finance team. The incident response plan requires the security team to receive these notices directly. What should the company configure?

  1. AAn SNS topic subscribed to the root user's mailbox
  2. BA new IAM user named security with console access
  3. CThe security alternate contact for the account
  4. DBusiness Support for the account
Show the answer and why
  • AAn SNS topic subscribed to the root user's mailbox

    Incorrect

    That still depends on the finance mailbox and is not how AWS sends account notices.

  • BA new IAM user named security with console access

    Incorrect

    IAM users do not receive AWS account notifications.

  • CThe security alternate contact for the account

    Correct

    Alternate contacts for billing, operations and security receive AWS communications in addition to the root user's email.

  • DBusiness Support for the account

    Incorrect

    A support plan does not change who receives security notices.

A distribution list as the security contact keeps notices flowing when people change roles.

Question 6 · choose 1

The incident response plan has responders capture memory from a suspect EC2 instance by running a forensic tool through Systems Manager Run Command. In a drill, Run Command could not reach many instances: they have no instance profile, so they are not managed nodes. Every instance uses IMDSv2 and SSM Agent 3.2.582.0 or later. The team wants all current and future instances in the account and Region to be ready for Run Command without attaching instance profiles. What should the team set up?

  1. AAn EC2 Instance Connect Endpoint in each VPC that has instances
  2. BGuardDuty Runtime Monitoring with automated agent configuration
  3. CDefault Host Management Configuration in Systems Manager
  4. DThe AWS Config managed rule ec2-instance-managed-by-systems-manager
Show the answer and why
  • AAn EC2 Instance Connect Endpoint in each VPC that has instances

    Incorrect

    The endpoint opens SSH or RDP connections to instances without public IP addresses; Run Command still works only on managed nodes.

  • BGuardDuty Runtime Monitoring with automated agent configuration

    Incorrect

    GuardDuty installs its runtime agent through Systems Manager, so this needs instances that are already managed nodes.

  • CDefault Host Management Configuration in Systems Manager

    Correct

    It applies a default IAM role so that Systems Manager manages all EC2 instances in the account and Region, with no instance profile to create.

  • DThe AWS Config managed rule ec2-instance-managed-by-systems-manager

    Incorrect

    The rule checks whether instances are managed by Systems Manager; it does not make them managed nodes.

Response tools need access in place before an incident. Default Host Management Configuration is turned on in each Region separately, and instances can take up to 30 minutes to pick up its role, so it belongs in preparation, not in the response.

Question 7 · choose 1

The company's threat intelligence team maintains a list of known malicious IP addresses. The team wants GuardDuty to raise findings when workloads communicate with those addresses. What should it configure?

  1. AA trusted IP address list with the malicious addresses
  2. BA network ACL that denies the addresses
  3. CA GuardDuty suppression rule for the addresses
  4. DA GuardDuty threat list with the malicious addresses
Show the answer and why
  • AA trusted IP address list with the malicious addresses

    Incorrect

    GuardDuty does not generate findings for entries in trusted lists, which is the opposite of what is needed.

  • BA network ACL that denies the addresses

    Incorrect

    Blocking traffic does not make GuardDuty report attempts.

  • CA GuardDuty suppression rule for the addresses

    Incorrect

    Suppression rules archive matching findings automatically.

  • DA GuardDuty threat list with the malicious addresses

    Correct

    GuardDuty generates findings for known malicious sources listed in threat lists.

Trusted lists reduce noise, threat lists add your own intelligence; both are set per account and Region.

Question 8 · choose 1

The response plan relies on one automation account that reacts to security events from all workload accounts. Events must reach it without copying automation into every account. What should the team set up?

  1. AA Lambda function in every account that emails the automation team
  2. BEventBridge rules that send events to a central event bus
  3. CCloudWatch dashboards shared with the automation account
  4. DSNS topics in every account with manual subscriptions
Show the answer and why
  • AA Lambda function in every account that emails the automation team

    Incorrect

    That copies code into every account and replaces automation with email.

  • BEventBridge rules that send events to a central event bus

    Correct

    EventBridge can send events between event buses in different accounts, and the receiving bus controls which accounts may send.

  • CCloudWatch dashboards shared with the automation account

    Incorrect

    Dashboards show metrics; they do not deliver events for automation.

  • DSNS topics in every account with manual subscriptions

    Incorrect

    Manual subscriptions add per-account work and do not filter events.

A resource-based policy on the central bus decides which accounts and rules may send to it.

Question 9 · choose 1

The incident response plan gives analysts a role in every account to review configurations and logs during an investigation, without being able to change resources. Which AWS managed policy fits this job function?

  1. AAdministratorAccess
  2. BPowerUserAccess
  3. CSecurityAudit
  4. DAWSSupportAccess
Show the answer and why
  • AAdministratorAccess

    Incorrect

    Full access lets analysts change or delete resources.

  • BPowerUserAccess

    Incorrect

    Power users can create and change most resources.

  • CSecurityAudit

    Correct

    SecurityAudit lets a user view configuration data and review logs to monitor accounts for compliance.

  • DAWSSupportAccess

    Incorrect

    This policy is for working with AWS Support cases.

Keep containment actions in a separate, more privileged role that is used only when needed.

Practise domain 2 →Practise all domains →