Skip to content
BytePatterns

SCS-C03 · Domain 2: Incident Response · 14% of the exam

Task 2.2: Respond to security events

Handling the event: preserving logs, snapshots and memory as forensic evidence, correlating logs across services, judging the scope of a finding, containing and cleaning up affected resources, restoring them, and finding the root cause with Detective.

Study it

  • Forensic evidence: snapshots, memory, logs and their custody

    Lesson coming

  • Containment and recovery: isolating instances, revoking credentials, restoring backups

    Lesson coming

  • Scope and root cause: validating findings and investigating with Detective

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 2

GuardDuty reports that an EC2 instance is communicating with a known command-and-control server. The instance must later be analyzed by the forensics team, including what was running in memory. Which actions preserve the evidence the team needs? (Choose TWO.)

  1. AStop the instance so that its volumes are consistent, then create an AMI
  2. BAcquire the instance memory with forensic tooling and store it in S3
  3. CTerminate the instance and launch a clean replacement from the latest AMI
  4. DSnapshot the attached EBS volumes and share them with the forensics account
  5. ETurn on VPC flow logs for the instance's subnet and keep them in S3
Show the answer and why
  • AStop the instance so that its volumes are consistent, then create an AMI

    Incorrect

    Stopping the instance discards the contents of memory, which the forensics team needs.

  • BAcquire the instance memory with forensic tooling and store it in S3

    Correct

    Memory holds running processes and connections that disk snapshots do not contain, so it is acquired from the running instance first.

  • CTerminate the instance and launch a clean replacement from the latest AMI

    Incorrect

    Termination deletes volumes set to delete on termination and loses memory, destroying evidence.

  • DSnapshot the attached EBS volumes and share them with the forensics account

    Correct

    Snapshots preserve the disks and can be restored to new volumes for analysis in a separate forensics account.

  • ETurn on VPC flow logs for the instance's subnet and keep them in S3

    Incorrect

    Flow logs record future network metadata only; they do not preserve the memory or disk state of the instance.

Capture what disappears first: memory from the running instance, then the disks as snapshots. Isolation with a restrictive security group follows memory acquisition in AWS's forensics orchestration.

Question 2 · choose 1

An attacker has an interactive session open to a compromised EC2 instance. The responder removed every inbound rule from the instance's security group, which allowed SSH only from a single office IP range, yet the attacker's existing session is still active. What should the responder do to cut the session immediately?

  1. AAdd network ACL deny rules for the instance's IP address on its subnet
  2. BRemove the outbound rules of the instance's security group as well
  3. CAttach a second security group to the instance that has no rules at all
  4. DRevoke the active sessions of the IAM role in the instance profile
Show the answer and why
  • AAdd network ACL deny rules for the instance's IP address on its subnet

    Correct

    Security groups keep allowing tracked connections after a rule changes. Network ACLs are stateless, so a deny breaks existing connections.

  • BRemove the outbound rules of the instance's security group as well

    Incorrect

    Changing a security group rule does not interrupt tracked connections; packets keep flowing until the connection times out.

  • CAttach a second security group to the instance that has no rules at all

    Incorrect

    Security group rules are cumulative and only allow traffic. An empty group adds nothing and the tracked connection continues.

  • DRevoke the active sessions of the IAM role in the instance profile

    Incorrect

    This denies the role's issued credentials for AWS API calls. It does not affect a network session to the instance.

A narrow SSH rule means the connection was tracked, so editing the security group does not drop it. A stateless network ACL deny does.

Question 3 · choose 1

Temporary credentials for an IAM role that a CI system assumes were printed in a public build log. The credentials are valid for several more hours. The team must stop anyone from using the exposed credentials now, while the CI system keeps working after it assumes the role again. What should the team do?

  1. ADeactivate the exposed access key ID in the IAM console
  2. BLower the role's maximum session duration to 15 minutes
  3. CDetach every permissions policy from the role
  4. DRevoke the role's active sessions in the IAM console
Show the answer and why
  • ADeactivate the exposed access key ID in the IAM console

    Incorrect

    Temporary security credentials are valid until they expire; they are not IAM user access keys that can be deactivated.

  • BLower the role's maximum session duration to 15 minutes

    Incorrect

    Credentials already issued stay valid for the duration they were issued with.

  • CDetach every permissions policy from the role

    Incorrect

    This stops the exposed credentials but also every new session, so the CI system stops working.

  • DRevoke the role's active sessions in the IAM console

    Correct

    IAM attaches AWSRevokeOlderSessions, which denies credentials issued before the revocation. Sessions started afterwards are not affected.

Role credentials cannot be deleted one by one; a deny conditioned on aws:TokenIssueTime invalidates everything issued before now and leaves new sessions working.

Question 4 · choose 1

GuardDuty reports unusual API activity by an IAM role. Without writing queries, an analyst wants to see the role's API call volume compared with its usual baseline over recent weeks, the IP addresses and user agents it used, and other findings that involve the same entities, to find how the activity started. Which service should the analyst use?

  1. AAmazon Athena queries over the CloudTrail logs
  2. BIAM Access Analyzer unused access findings
  3. CAmazon Detective
  4. DSecurity Hub CSPM insights grouped by resource
Show the answer and why
  • AAmazon Athena queries over the CloudTrail logs

    Incorrect

    Athena can answer these questions, but only with queries the analyst writes, which the requirement rules out.

  • BIAM Access Analyzer unused access findings

    Incorrect

    Unused access findings show permissions and roles that are not used. They do not reconstruct a suspicious activity's history.

  • CAmazon Detective

    Correct

    Detective builds a behavior graph from logs and gives prebuilt visualizations and finding groups to find the root cause of a finding.

  • DSecurity Hub CSPM insights grouped by resource

    Incorrect

    Insights group findings; they do not show an entity's API activity or its baseline.

Root cause analysis from a finding, with baselines and related entities already visualized, is what Detective is for.

Question 5 · choose 1

GuardDuty reports UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.OutsideAWS for several instances. The VPC sends internet traffic through a Site-to-Site VPN to the company's on-premises internet gateway, and the API caller IP in every finding is that gateway's address. The activity matches normal application calls. What should the security team do?

  1. ACreate a suppression rule for this finding type and the gateway's API caller IP range
  2. BRevoke the instance roles' sessions and isolate the instances with a restrictive security group
  3. CCreate a suppression rule for this finding type for all API caller addresses
  4. DArchive the findings by hand in the GuardDuty console whenever they appear
Show the answer and why
  • ACreate a suppression rule for this finding type and the gateway's API caller IP range

    Correct

    Traffic that egresses through an on-premises gateway is a known cause of this finding; GuardDuty recommends suppressing it with exactly these two criteria.

  • BRevoke the instance roles' sessions and isolate the instances with a restrictive security group

    Incorrect

    Containment fits a real compromise. Here the evidence shows expected traffic, so this would disrupt the application for no reason.

  • CCreate a suppression rule for this finding type for all API caller addresses

    Incorrect

    A rule on the finding type alone would also hide real credential theft from other addresses.

  • DArchive the findings by hand in the GuardDuty console whenever they appear

    Incorrect

    Manual archiving keeps the noise and the work. A suppression rule archives matching new findings automatically.

Validating a finding includes ruling out a benign cause. When the cause is a known network design, suppress narrowly so real exfiltration from any other address still raises a finding.

Question 6 · choose 1

A responder learns that a developer made several S3 buckets in a production account public by mistake. No bucket in the account should ever be public. What is the fastest way to contain the exposure?

  1. ADelete every bucket that was made public
  2. BTurn on S3 Block Public Access for the account
  3. CRotate the developer's IAM access keys right away
  4. DTurn on default encryption for the buckets
Show the answer and why
  • ADelete every bucket that was made public

    Incorrect

    Deleting buckets destroys data and evidence.

  • BTurn on S3 Block Public Access for the account

    Correct

    Account-level Block Public Access overrides public bucket policies and ACLs for every bucket in the account.

  • CRotate the developer's IAM access keys right away

    Incorrect

    Rotation does not remove the public access that already exists.

  • DTurn on default encryption for the buckets

    Incorrect

    Encryption at rest does not stop public reads through S3.

After containing, review access logs or data events to see what was read while the buckets were public.

Question 7 · choose 1

A review finds that a manual RDS snapshot of a customer database was shared with visibility set to Public. What should the responder do first?

  1. AMake the shared snapshot private again
  2. BEncrypt the source database instance in place
  3. CTake a new snapshot of the database
  4. DRotate the database master password
Show the answer and why
  • AMake the shared snapshot private again

    Correct

    A public snapshot lets all AWS accounts restore it; setting it to Private stops that sharing.

  • BEncrypt the source database instance in place

    Incorrect

    That does not change the snapshot that is already shared.

  • CTake a new snapshot of the database

    Incorrect

    A new snapshot leaves the public one shared.

  • DRotate the database master password

    Incorrect

    Anyone restoring the snapshot can reset the password of the copy.

Then check CloudTrail for the sharing call and whether other accounts copied or restored the snapshot.

Question 8 · choose 1

The private key of an EC2 key pair was found in a public code repository. The team deleted the key pair in the EC2 console. Which statement is true?

  1. AThe private key no longer works on any instance
  2. BDeleting the key pair also rotates the instances' host keys
  3. CInstances launched with it still accept the private key
  4. DInstances launched with the key are stopped automatically
Show the answer and why
  • AThe private key no longer works on any instance

    Incorrect

    Deleting the key pair does not remove the public key from instances, so the private key still works.

  • BDeleting the key pair also rotates the instances' host keys

    Incorrect

    Key pair deletion touches only the public key stored in EC2.

  • CInstances launched with it still accept the private key

    Correct

    The public key stays on instances where it was added, so it must be removed from them as well.

  • DInstances launched with the key are stopped automatically

    Incorrect

    EC2 does not stop instances when a key pair is deleted.

Remove the public key from each instance's authorized keys, and prefer Session Manager or EC2 Instance Connect over long-lived keys.

Question 9 · choose 1

The private key of an ACM exportable public certificate was copied by an attacker from a compromised web server. What should the team do with the certificate?

  1. ADelete the certificate from the web server only
  2. BImport the certificate into ACM again
  3. CWait for ACM to renew the certificate
  4. DRevoke the certificate in ACM, then reissue
Show the answer and why
  • ADelete the certificate from the web server only

    Incorrect

    The attacker's copy of the key stays valid with the certificate.

  • BImport the certificate into ACM again

    Incorrect

    Re-importing does not invalidate the stolen key.

  • CWait for ACM to renew the certificate

    Incorrect

    Until renewal, the old certificate and stolen key stay valid.

  • DRevoke the certificate in ACM, then reissue

    Correct

    ACM exportable public certificates can be revoked; a revoked certificate cannot be reused.

Revocation is permanent, so deploy the replacement certificate before or right after revoking.

Question 10 · choose 1

An attacker published malicious code as a new version of a Lambda function. Callers invoke the function through an alias, and the version before the attack is known to be good. What is the fastest way to stop the malicious code from running?

  1. APoint the alias back to the earlier good version
  2. BDelete the alias and redeploy the function from source
  3. CTurn on code signing and wait for the next deployment
  4. DChange the function's memory setting to force a restart
Show the answer and why
  • APoint the alias back to the earlier good version

    Correct

    An alias is a pointer to a function version that you can update, so callers move back immediately.

  • BDelete the alias and redeploy the function from source

    Incorrect

    Rebuilding takes longer and removes evidence.

  • CTurn on code signing and wait for the next deployment

    Incorrect

    Code signing helps prevent future changes; it does not undo this one.

  • DChange the function's memory setting to force a restart

    Incorrect

    A configuration change does not replace the malicious code.

Then find out how the attacker could publish code and remove that access.

Practise domain 2 →Practise all domains →