AWS 2: Incident Response: 125 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS 2: Incident Response: 125 practice questions

AWS 125 questions 12 shown free

12 of the 125 2: Incident Response questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for AWS? Take the free 5-min readiness check →

1. Run AWSSupport-ContainEC2Instance and restore the saved: Which design best meets these constraints?

Medium
A multi-account analytics environment receives a high-severity GuardDuty finding involving an EC2 instance in a production account. The response team must preserve the running instance for evidence, block new network connections; existing tracked flows will be assessed separately, and avoid deleting or stopping the instance before investigators inspect it. The organization already configured the required AWS Security Incident Response permissions and containment preferences. The response must be reversible after the investigation. Which design best meets these constraints?
  1. Attach an additional restrictive security group while leaving the instance running.
    Adding a security group is additive and cannot reliably remove permissions granted by existing security groups.
  2. Terminate the EC2 instance immediately and restore it from the latest Amazon EBS snapshot.
    Termination destroys volatile evidence and does not preserve the original running system for investigators.
  3. Remove the instance from its target group and leave its existing security groups unchanged.
    Target-group removal limits application routing but does not prevent other network communications from the instance.
  4. Run AWSSupport-ContainEC2Instance and restore the saved security groups after investigation. ✓
    The supported containment automation keeps the instance running and intact, replaces its security groups to block new network activity, and permits reversal after the investigation.
The trap
Assumes security-group attachment replaces existing permissions. Mistakes application deregistration for comprehensive network containment. Prioritizes replacement over evidence preservation and reversible containment.

Use reversible EC2 containment to isolate the instance while preserving its running state for forensic investigation.

2. Use Systems Manager Session Manager with IAM-scoped access: Which TWO preparations should the security enginee

Medium
A financial services organization prepares for incidents involving privileged administrators and sensitive EC2 workloads. Security requires investigators to access managed nodes without inbound SSH, preserve session activity for review, and restrict emergency actions so operators cannot run arbitrary remediation against every account. The organization has already deployed SSM Agent, configured private connectivity, and created encrypted S3 and CloudWatch Logs destinations. Which TWO preparations should the security engineer implement? Select TWO.

Select two. More than one option is correct — every correct one is ticked below.

  1. Open inbound SSH from the corporate network and require administrators to rotate keys monthly.
    SSH exposure and key administration weaken the stated requirement to avoid inbound management ports.
  2. Use an EC2 bastion host with port forwarding and store its operating-system logs in Amazon S3.
    A bastion adds a management surface and its host logs do not inherently provide Session Manager activity records.
  3. Use Systems Manager Session Manager with IAM-scoped access and log sessions to CloudWatch Logs. ✓
    Session Manager avoids inbound SSH and records session activity while IAM policies restrict users and target nodes.
  4. Create a Systems Manager Automation runbook with least-privilege roles and require approval before disruptive actions. ✓
    Automation runbooks standardize emergency work and approval gates limit unauthorized or overly broad remediation.
  5. Grant administrators broad account-wide AdministratorAccess for emergency response and record only CloudTrail API calls.
    Broad permissions violate least privilege, while CloudTrail does not capture the commands typed inside a session.
The trap
Treats network restriction and key rotation as equivalent to Session Manager control. Confuses API-call auditing with session-command logging and emergency authorization control. Assumes centralized bastion logging satisfies managed-node session auditing.

Prepare controlled Session Manager access and approval-gated Automation runbooks for auditable emergency operations.

3. Run the containment automation in staging: Which procedure best validates both the technical runbook and recov

Medium
A software delivery platform has an incident response plan that requires isolating a compromised application instance, preserving evidence, notifying responders, and restoring service from a verified recovery point. Leadership wants evidence that the plan works in practice, but production traffic cannot be intentionally disrupted. The team has a representative staging environment and can schedule controlled experiments with documented stop conditions. Which procedure best validates both the technical runbook and recovery objectives?
  1. Conduct a tabletop in which responders review containment, evidence preservation, notification, restoration, deployment timing, failover timing, and recovery-point objectives.
    A tabletop tests coordination and decisions but does not execute containment or prove that a backup can be restored.
  2. Run the containment automation against production during a maintenance window and measure customer-request failures, restore timing, and recovery-point performance.
    Intentional production disruption violates the constraint, even if performed during a scheduled window.
  3. Run the containment automation in staging, restore a verified backup, and record deployment, failover, RTO, and RPO. ✓
    An authorized staging experiment with stop conditions executes the containment workflow, and an actual restore tests recovery. Record deployment timing, containment, notification, failover or restore actions, and observed RTO/RPO; these are test results, not service-wide guarantees.
  4. Compare backup timestamps with the objectives, inspect the automation definition, and approve the runbook without running containment or restoration.
    Configuration and timestamp evidence cannot demonstrate actual containment, deployment, failover, restore timing, or recoverability.
The trap
Assumes production impact is necessary for credible technical evidence. Confuses discussion-based validation with technical execution. Treats design evidence as operational test evidence.

Test approved staging faults and perform an actual verified-backup restore.

4. Invoke a Systems Manager Automation runbook: Which design should be implemented?

Medium
An enterprise SaaS provider receives a GuardDuty finding for an EC2 instance that is processing customer requests. The security team must automatically isolate the instance, preserve it for later forensics, and limit remediation to tagged production instances in the affected account. The workflow must require human approval before destructive actions and must stop if too many targets fail. EventBridge can invoke the response workflow, and the required Automation service role already exists. Which design should be implemented?
  1. Invoke a Systems Manager Automation runbook from EventBridge using target tags, approval steps, and rate controls. ✓
    Automation supports event-driven execution, tag targeting, approvals, concurrency, and error thresholds for controlled remediation.
  2. Use an EventBridge rule to disable GuardDuty after the finding and wait for operators to investigate manually.
    Disabling detection removes security visibility and does not isolate the affected workload.
  3. Start an Automation runbook that immediately stops all tagged instances without approval or error thresholds.
    Stopping every matching instance is disruptive and omits the required approval and failure safeguards.
  4. Invoke a Lambda function that terminates every instance sharing the finding account.
    Account-wide termination is destructive, ignores target tags, and prevents forensic preservation before approval.
The trap
Confuses rapid remediation with scoped, reversible incident handling. Uses valid Automation but violates the stated safety controls and preservation objective. Treats suppressing alerts as containment.

Use EventBridge and Systems Manager Automation with tag targeting, approvals, and rate controls for scoped remediation.

5. Send system and application logs to CloudWatch Logs: Which collection design is most appropriate?

Medium
A media company investigates suspected compromise of an EC2 transcoding fleet. Investigators need operating-system logs, application logs, DNS queries, and recoverable disk images. Evidence must be collected before replacement, protected from alteration, and accompanied by identity, timestamps, hashes, and access history. The centralized security account has an encrypted S3 bucket with versioning and S3 Object Lock compliance retention. Which collection design is most appropriate?
  1. Stream system and application logs to CloudWatch Logs, enable VPC Flow Logs, and snapshot EBS volumes before replacement.
    VPC Flow Logs provide network metadata, not DNS query records. The design therefore misses a stated evidence source.
  2. Send system and application logs to CloudWatch Logs, enable Resolver query logging, snapshot EBS volumes before replacement, and preserve artifacts with hashes and controlled access. ✓
    Each required evidence source has an appropriate producer, collection occurs before replacement, and the stated retention and custody controls protect the resulting artifacts.
  3. Replace compromised instances, then snapshot the replacement fleet and collect its logs.
    The original host state is lost or changed before acquisition, so the resulting artifacts do not reliably represent the compromised instances.
  4. Enable S3 Object Lock for exported logs and assume retained objects remain readable if the customer KMS key becomes unavailable.
    Object Lock protects retained versions from alteration or deletion; it does not restore readability when the encryption key is unavailable.
The trap
Treats flow metadata as equivalent to DNS query logging. Reverses the required preservation order. Confuses immutability with encryption-key availability.

Use complementary host, application, DNS, and disk collection before replacement, then protect artifacts with custody controls.

6. Query normalized Security Lake data to correlate: Which TWO actions should investigators take?

Medium
A hybrid identity deployment uses on-premises Active Directory, AWS IAM Identity Center, and applications running in multiple AWS accounts. Investigators suspect credential misuse and need to correlate authentication activity with AWS API calls, VPC connections, and EKS audit events. Logs are already centralized in Amazon Security Lake for the relevant Regions, and the security team needs both normalized cross-source searches and relationship-based investigation around a GuardDuty finding. Which TWO actions should investigators take? Select TWO.

Select two. More than one option is correct — every correct one is ticked below.

  1. Query normalized Security Lake data to correlate CloudTrail, VPC Flow Logs, and EKS audit events. ✓
    Security Lake normalizes supported sources, enabling cross-source searches across the relevant AWS activity records.
  2. Search only each account's local CloudTrail console because centralized logs cannot be correlated across accounts.
    Centralized Security Lake data and Detective are specifically designed to support broader investigation workflows.
  3. Use Amazon Detective to examine entities and activity relationships associated with the GuardDuty finding. ✓
    Detective aggregates related security data and visualizes entities, findings, and activity for root-cause analysis.
  4. Use Route 53 Resolver query logs as the sole source for correlating IAM authentication and AWS API activity.
    Resolver logs describe DNS queries and cannot represent IAM authentication or CloudTrail API activity comprehensively.
  5. Use Amazon Inspector findings to reconstruct the identities and network sequence behind the suspected credential misuse.
    Inspector focuses on vulnerability and exposure assessment rather than event correlation and identity investigation.
The trap
Treats DNS telemetry as an identity and API audit trail. Confuses vulnerability assessment with incident investigation. Assumes account boundaries prevent centralized security analysis.

Use Security Lake for normalized cross-source searches and Detective for relationship-based GuardDuty investigation.

7. Use Detective finding groups and entity timelines: Which investigation approach provides the strongest validat

Medium
A centralized security operations team receives a high-severity GuardDuty finding indicating possible credential misuse in a member account. The team must determine whether the activity affected additional IAM principals, EC2 instances, or data-access paths before authorizing containment. Investigators have access to the organization’s Detective behavior graph and the raw CloudTrail and VPC Flow Logs stored in Security Lake. Which investigation approach provides the strongest validation of scope and impact?
  1. Use backup-restore results to identify IAM principals that accessed the affected data.
    Restore testing validates recoverability; it does not provide identity or access-event evidence.
  2. Review the finding’s source address and block that address at the VPC perimeter.
    A source address cannot establish all affected principals, resources, or credential-based activity.
  3. Treat the GuardDuty severity as proof that every resource in the member account is compromised and authorize account-wide containment.
    Severity expresses potential risk; it does not prove account-wide compromise or justify indiscriminate containment.
  4. Use Detective finding groups and entity timelines, then query raw Security Lake records to confirm API and network events. ✓
    Detective provides relationships and historical context, while the raw records corroborate specific principals, resources, API calls, and network activity.
The trap
Reduces a multi-resource investigation to one network indicator. Confuses recovery validation with incident-scope analysis. Treats a detection assessment as complete scope evidence.

Correlate Detective context with raw Security Lake evidence before authorizing containment.

8. Preserve evidence: Which response sequence is most appropriate?

Medium
A regulated research workload runs on EC2 and stores sensitive experiment results in Amazon S3. GuardDuty identifies suspicious activity from one instance, and investigators confirm the instance role credentials may be compromised. Evidence must be preserved, access must be contained without destroying resources, and the workload must eventually return from a verified clean state. Existing backup recovery points are available, and the organization has configured reversible Security Incident Response containment roles. Which response sequence is most appropriate?
  1. Disable GuardDuty, continue serving traffic, and rotate the role only after investigators finish reviewing the workload.
    Disabling detection and delaying credential containment allow suspected misuse to continue during investigation.
  2. Terminate the instance, delete the bucket, and rebuild from the newest available recovery point after confirming the backup timestamp.
    Termination and deletion can destroy evidence or data, and recency alone does not establish that a recovery point is clean.
  3. Restrict the instance with a security group, reboot it, and immediately restore production traffic while leaving the role active.
    This leaves potentially compromised credentials active, and rebooting does not establish eradication or a clean state.
  4. Preserve evidence, contain the instance and role, investigate persistence, restore a verified-clean point, and validate before recovery. ✓
    This sequence preserves evidence, applies reversible EC2 and IAM containment, addresses persistence, and returns service only after recovery validation. EC2 security-group containment blocks new activity but does not necessarily terminate tracked flows.
The trap
Confuses irreversible destruction and backup recency with containment and integrity. Assumes network restriction and reboot remove credential compromise. Prioritizes uninterrupted service over stopping active credential misuse.

Preserve evidence, contain both workload and identity, eradicate persistence, then recover from a verified clean point.

9. Use Amazon Detective to review the related GuardDuty: Which approach best supports root cause analysis?

Medium
An incident response team investigates a compromised IAM role suspected of accessing unfamiliar resources. CloudTrail records span 11 months, GuardDuty produced several related findings, and investigators must identify the initiating principal without altering evidence. The team wants an efficient method that correlates entities, activity, and findings across the investigation window. Which approach best supports root cause analysis?
  1. Search CloudTrail manually for the latest API call made by the suspicious role.
    This may identify activity but does not efficiently correlate related entities, findings, and historical behavior across the investigation.
  2. Use Amazon Detective to review the related GuardDuty finding group and connected entities. ✓
    Detective correlates findings, entities, and historical activity, supporting investigation of likely initiating actions and root cause.
  3. Use Amazon Inspector findings to review workload vulnerabilities associated with the role.
    Inspector assesses workload vulnerabilities; it does not provide the required correlation of IAM activity, entities, and related findings.
  4. Export GuardDuty findings to Amazon S3 and compare timestamps with deployment records.
    Timestamp comparison provides context but does not automatically connect principals, resources, activities, and related findings.
The trap
Confuses vulnerability assessment with behavioral investigation. Assumes the latest call identifies the initiating event. Treats isolated timestamps as causal evidence.

Amazon Detective correlates findings, entities, and historical activity for root cause investigation.

10. Run IAM containment to attach a deny-all policy: Which TWO actions should the runbook perform first?

Medium
A cross-Region archive experiences suspected credential misuse. The response plan requires preserving affected instances for later analysis, immediately restricting the compromised principal, and coordinating actions across accounts and Regions. Analysts have confirmed the principal is an IAM role used by automation, while the instances must remain running for business continuity. Which TWO actions should the runbook perform first? Select TWO.

Select two. More than one option is correct — every correct one is ticked below.

  1. Run IAM containment to attach a deny-all policy to the compromised role. ✓
    The supported IAM containment action preserves the role while reversibly denying its ability to perform actions.
  2. Change the archive subnets’ network ACLs to deny all traffic before documenting resources.
    Subnet-wide denial can disrupt unrelated systems and does not directly contain the confirmed IAM role before evidence is documented.
  3. Use an SCP to deny actions for every role in the archive accounts.
    An SCP is an organizational permission control, not an incident-specific operation that directly disables the confirmed role; broad denial also creates unnecessary impact.
  4. Terminate the affected instances and restore them from the newest backups.
    Termination can destroy evidence and restoration should wait until backups are verified clean and recovery is authorized.
  5. Replace each affected instance’s security groups with restrictive groups through EC2 containment automation. ✓
    EC2 containment replaces the instance security groups with a restrictive containment group while leaving the instances running for analysis.
The trap
Confuses organization-wide guardrails with targeted containment. Uses broad subnet containment without respecting scope or sequencing. Performs irreversible recovery before preservation and containment.

Contain the confirmed role and isolate affected running instances while preserving evidence.

11. Enable GuardDuty Runtime Monitoring for EKS and configure: Which configuration best prepares the environment f

Hard
A generative AI application runs inference workers on Amazon EKS managed node groups. A GuardDuty finding indicates suspicious process execution in one worker, and the security team needs runtime evidence before replacing workloads. The cluster uses private subnets, workloads have tightly scoped IAM roles, and analysts require visibility into processes, command-line arguments, file access, and network connections. Which configuration best prepares the environment for this incident?
  1. Enable GuardDuty Runtime Monitoring for EKS and configure the security agent for the managed nodes. ✓
    Runtime Monitoring supplies process, command-line, file, and network visibility for supported EKS workloads before disruptive replacement.
  2. Enable GuardDuty S3 Protection for application buckets and investigate worker activity through object events.
    S3 Protection addresses object-access threats and cannot provide runtime evidence from EKS worker processes.
  3. Enable Amazon Inspector scanning for the EKS node AMIs and review discovered package vulnerabilities.
    Inspector vulnerability findings help identify software weaknesses but do not provide the requested runtime behavior evidence.
  4. Enable VPC Flow Logs for worker subnets and use them as the sole source of process execution evidence.
    VPC Flow Logs provide network metadata, not process execution, command-line arguments, or file-access visibility.
The trap
This assumes network-flow records expose host-level runtime behavior. This selects a data-protection control unrelated to the affected workload’s runtime telemetry. This confuses vulnerability assessment with runtime threat detection.

GuardDuty Runtime Monitoring with its EKS security agent captures the workload-level evidence needed before replacing suspicious workers.

12. Create an AWS Backup restore testing plan: Which procedure best improves the next exercise?

Hard
A retail security team runs a quarterly response exercise against a staging checkout stack. The plan requires validating that responders can restore a database, meet the documented recovery-time objective, and verify restored data before the exercise closes. During the latest test, the restore completed, but responders recorded no completion duration and accepted the database without validation. Which procedure best improves the next exercise? Exhibit: exercise record: “restore job completed; duration: blank; validation: not performed; production traffic: unaffected.”
  1. Use AWS Resilience Hub assessment results as proof that the completed restore met the recovery-time objective.
    Resilience Hub assesses application resilience but cannot prove that this specific restore completed within the exercise objective.
  2. Create an AWS Backup restore testing plan, monitor restore duration, and use restore testing validation afterward. ✓
    Restore testing measures restore completion time and supports optional validation before temporary test resources are removed.
  3. Run an on-demand AWS Backup restore and rely on CloudTrail StartRestoreJob events as validation evidence.
    CloudTrail confirms restore API activity but does not validate restored data or measure the exercise against recovery objectives.
  4. Use AWS Fault Injection Service to terminate the database and assume successful restoration demonstrates plan effectiveness.
    Fault Injection Service can test disruption responses but does not itself validate restored data or record restore-job duration.
The trap
This mistakes an audit event for functional recovery validation. This substitutes failure injection for the missing restore validation controls. This treats a resilience assessment as evidence of an executed restore test.

AWS Backup restore testing records restore duration and supports validation, directly addressing both missing measurements in the exercise record.

113 more 2: Incident Response questions

The remaining 113 questions in this domain are part of the full AWS bank — 890 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your AWS readiness — free

Other AWS domains

Part of the Certsqill AWS question bank · 2: Incident Response · Every answer, right and wrong, comes with its own explanation.