AWS 2: Incident Response: 125 practice questions
12 of the 125 2: Incident Response questions in the Certsqill AWS bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for AWS? Take the free 5-min readiness check →
1. Run AWSSupport-ContainEC2Instance and restore the saved: Which design best meets these constraints?
- Attach an additional restrictive security group while leaving the instance running.Adding a security group is additive and cannot reliably remove permissions granted by existing security groups.
- Terminate the EC2 instance immediately and restore it from the latest Amazon EBS snapshot.Termination destroys volatile evidence and does not preserve the original running system for investigators.
- Remove the instance from its target group and leave its existing security groups unchanged.Target-group removal limits application routing but does not prevent other network communications from the instance.
- Run AWSSupport-ContainEC2Instance and restore the saved security groups after investigation. ✓The supported containment automation keeps the instance running and intact, replaces its security groups to block new network activity, and permits reversal after the investigation.
Use reversible EC2 containment to isolate the instance while preserving its running state for forensic investigation.
2. Use Systems Manager Session Manager with IAM-scoped access: Which TWO preparations should the security enginee
Select two. More than one option is correct — every correct one is ticked below.
- Open inbound SSH from the corporate network and require administrators to rotate keys monthly.SSH exposure and key administration weaken the stated requirement to avoid inbound management ports.
- Use an EC2 bastion host with port forwarding and store its operating-system logs in Amazon S3.A bastion adds a management surface and its host logs do not inherently provide Session Manager activity records.
- Use Systems Manager Session Manager with IAM-scoped access and log sessions to CloudWatch Logs. ✓Session Manager avoids inbound SSH and records session activity while IAM policies restrict users and target nodes.
- Create a Systems Manager Automation runbook with least-privilege roles and require approval before disruptive actions. ✓Automation runbooks standardize emergency work and approval gates limit unauthorized or overly broad remediation.
- Grant administrators broad account-wide AdministratorAccess for emergency response and record only CloudTrail API calls.Broad permissions violate least privilege, while CloudTrail does not capture the commands typed inside a session.
Prepare controlled Session Manager access and approval-gated Automation runbooks for auditable emergency operations.
3. Run the containment automation in staging: Which procedure best validates both the technical runbook and recov
- Conduct a tabletop in which responders review containment, evidence preservation, notification, restoration, deployment timing, failover timing, and recovery-point objectives.A tabletop tests coordination and decisions but does not execute containment or prove that a backup can be restored.
- Run the containment automation against production during a maintenance window and measure customer-request failures, restore timing, and recovery-point performance.Intentional production disruption violates the constraint, even if performed during a scheduled window.
- Run the containment automation in staging, restore a verified backup, and record deployment, failover, RTO, and RPO. ✓An authorized staging experiment with stop conditions executes the containment workflow, and an actual restore tests recovery. Record deployment timing, containment, notification, failover or restore actions, and observed RTO/RPO; these are test results, not service-wide guarantees.
- Compare backup timestamps with the objectives, inspect the automation definition, and approve the runbook without running containment or restoration.Configuration and timestamp evidence cannot demonstrate actual containment, deployment, failover, restore timing, or recoverability.
Test approved staging faults and perform an actual verified-backup restore.
4. Invoke a Systems Manager Automation runbook: Which design should be implemented?
- Invoke a Systems Manager Automation runbook from EventBridge using target tags, approval steps, and rate controls. ✓Automation supports event-driven execution, tag targeting, approvals, concurrency, and error thresholds for controlled remediation.
- Use an EventBridge rule to disable GuardDuty after the finding and wait for operators to investigate manually.Disabling detection removes security visibility and does not isolate the affected workload.
- Start an Automation runbook that immediately stops all tagged instances without approval or error thresholds.Stopping every matching instance is disruptive and omits the required approval and failure safeguards.
- Invoke a Lambda function that terminates every instance sharing the finding account.Account-wide termination is destructive, ignores target tags, and prevents forensic preservation before approval.
Use EventBridge and Systems Manager Automation with tag targeting, approvals, and rate controls for scoped remediation.
5. Send system and application logs to CloudWatch Logs: Which collection design is most appropriate?
- Stream system and application logs to CloudWatch Logs, enable VPC Flow Logs, and snapshot EBS volumes before replacement.VPC Flow Logs provide network metadata, not DNS query records. The design therefore misses a stated evidence source.
- Send system and application logs to CloudWatch Logs, enable Resolver query logging, snapshot EBS volumes before replacement, and preserve artifacts with hashes and controlled access. ✓Each required evidence source has an appropriate producer, collection occurs before replacement, and the stated retention and custody controls protect the resulting artifacts.
- Replace compromised instances, then snapshot the replacement fleet and collect its logs.The original host state is lost or changed before acquisition, so the resulting artifacts do not reliably represent the compromised instances.
- Enable S3 Object Lock for exported logs and assume retained objects remain readable if the customer KMS key becomes unavailable.Object Lock protects retained versions from alteration or deletion; it does not restore readability when the encryption key is unavailable.
Use complementary host, application, DNS, and disk collection before replacement, then protect artifacts with custody controls.
6. Query normalized Security Lake data to correlate: Which TWO actions should investigators take?
Select two. More than one option is correct — every correct one is ticked below.
- Query normalized Security Lake data to correlate CloudTrail, VPC Flow Logs, and EKS audit events. ✓Security Lake normalizes supported sources, enabling cross-source searches across the relevant AWS activity records.
- Search only each account's local CloudTrail console because centralized logs cannot be correlated across accounts.Centralized Security Lake data and Detective are specifically designed to support broader investigation workflows.
- Use Amazon Detective to examine entities and activity relationships associated with the GuardDuty finding. ✓Detective aggregates related security data and visualizes entities, findings, and activity for root-cause analysis.
- Use Route 53 Resolver query logs as the sole source for correlating IAM authentication and AWS API activity.Resolver logs describe DNS queries and cannot represent IAM authentication or CloudTrail API activity comprehensively.
- Use Amazon Inspector findings to reconstruct the identities and network sequence behind the suspected credential misuse.Inspector focuses on vulnerability and exposure assessment rather than event correlation and identity investigation.
Use Security Lake for normalized cross-source searches and Detective for relationship-based GuardDuty investigation.
7. Use Detective finding groups and entity timelines: Which investigation approach provides the strongest validat
- Use backup-restore results to identify IAM principals that accessed the affected data.Restore testing validates recoverability; it does not provide identity or access-event evidence.
- Review the finding’s source address and block that address at the VPC perimeter.A source address cannot establish all affected principals, resources, or credential-based activity.
- Treat the GuardDuty severity as proof that every resource in the member account is compromised and authorize account-wide containment.Severity expresses potential risk; it does not prove account-wide compromise or justify indiscriminate containment.
- Use Detective finding groups and entity timelines, then query raw Security Lake records to confirm API and network events. ✓Detective provides relationships and historical context, while the raw records corroborate specific principals, resources, API calls, and network activity.
Correlate Detective context with raw Security Lake evidence before authorizing containment.
8. Preserve evidence: Which response sequence is most appropriate?
- Disable GuardDuty, continue serving traffic, and rotate the role only after investigators finish reviewing the workload.Disabling detection and delaying credential containment allow suspected misuse to continue during investigation.
- Terminate the instance, delete the bucket, and rebuild from the newest available recovery point after confirming the backup timestamp.Termination and deletion can destroy evidence or data, and recency alone does not establish that a recovery point is clean.
- Restrict the instance with a security group, reboot it, and immediately restore production traffic while leaving the role active.This leaves potentially compromised credentials active, and rebooting does not establish eradication or a clean state.
- Preserve evidence, contain the instance and role, investigate persistence, restore a verified-clean point, and validate before recovery. ✓This sequence preserves evidence, applies reversible EC2 and IAM containment, addresses persistence, and returns service only after recovery validation. EC2 security-group containment blocks new activity but does not necessarily terminate tracked flows.
Preserve evidence, contain both workload and identity, eradicate persistence, then recover from a verified clean point.
9. Use Amazon Detective to review the related GuardDuty: Which approach best supports root cause analysis?
- Search CloudTrail manually for the latest API call made by the suspicious role.This may identify activity but does not efficiently correlate related entities, findings, and historical behavior across the investigation.
- Use Amazon Detective to review the related GuardDuty finding group and connected entities. ✓Detective correlates findings, entities, and historical activity, supporting investigation of likely initiating actions and root cause.
- Use Amazon Inspector findings to review workload vulnerabilities associated with the role.Inspector assesses workload vulnerabilities; it does not provide the required correlation of IAM activity, entities, and related findings.
- Export GuardDuty findings to Amazon S3 and compare timestamps with deployment records.Timestamp comparison provides context but does not automatically connect principals, resources, activities, and related findings.
Amazon Detective correlates findings, entities, and historical activity for root cause investigation.
10. Run IAM containment to attach a deny-all policy: Which TWO actions should the runbook perform first?
Select two. More than one option is correct — every correct one is ticked below.
- Run IAM containment to attach a deny-all policy to the compromised role. ✓The supported IAM containment action preserves the role while reversibly denying its ability to perform actions.
- Change the archive subnets’ network ACLs to deny all traffic before documenting resources.Subnet-wide denial can disrupt unrelated systems and does not directly contain the confirmed IAM role before evidence is documented.
- Use an SCP to deny actions for every role in the archive accounts.An SCP is an organizational permission control, not an incident-specific operation that directly disables the confirmed role; broad denial also creates unnecessary impact.
- Terminate the affected instances and restore them from the newest backups.Termination can destroy evidence and restoration should wait until backups are verified clean and recovery is authorized.
- Replace each affected instance’s security groups with restrictive groups through EC2 containment automation. ✓EC2 containment replaces the instance security groups with a restrictive containment group while leaving the instances running for analysis.
Contain the confirmed role and isolate affected running instances while preserving evidence.
11. Enable GuardDuty Runtime Monitoring for EKS and configure: Which configuration best prepares the environment f
- Enable GuardDuty Runtime Monitoring for EKS and configure the security agent for the managed nodes. ✓Runtime Monitoring supplies process, command-line, file, and network visibility for supported EKS workloads before disruptive replacement.
- Enable GuardDuty S3 Protection for application buckets and investigate worker activity through object events.S3 Protection addresses object-access threats and cannot provide runtime evidence from EKS worker processes.
- Enable Amazon Inspector scanning for the EKS node AMIs and review discovered package vulnerabilities.Inspector vulnerability findings help identify software weaknesses but do not provide the requested runtime behavior evidence.
- Enable VPC Flow Logs for worker subnets and use them as the sole source of process execution evidence.VPC Flow Logs provide network metadata, not process execution, command-line arguments, or file-access visibility.
GuardDuty Runtime Monitoring with its EKS security agent captures the workload-level evidence needed before replacing suspicious workers.
12. Create an AWS Backup restore testing plan: Which procedure best improves the next exercise?
- Use AWS Resilience Hub assessment results as proof that the completed restore met the recovery-time objective.Resilience Hub assesses application resilience but cannot prove that this specific restore completed within the exercise objective.
- Create an AWS Backup restore testing plan, monitor restore duration, and use restore testing validation afterward. ✓Restore testing measures restore completion time and supports optional validation before temporary test resources are removed.
- Run an on-demand AWS Backup restore and rely on CloudTrail StartRestoreJob events as validation evidence.CloudTrail confirms restore API activity but does not validate restored data or measure the exercise against recovery objectives.
- Use AWS Fault Injection Service to terminate the database and assume successful restoration demonstrates plan effectiveness.Fault Injection Service can test disruption responses but does not itself validate restored data or record restore-job duration.
AWS Backup restore testing records restore duration and supports validation, directly addressing both missing measurements in the exercise record.
113 more 2: Incident Response questions
The remaining 113 questions in this domain are part of the full AWS bank — 890 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your AWS readiness — freeOther AWS domains
- 4: Identity and Access Management — 178 questions →
- 3: Infrastructure Security — 160 questions →
- 5: Data Protection — 160 questions →
- 1: Detection — 142 questions →
- 6: Security Foundations and Governance — 125 questions →
- All 890 AWS questions →
- AWS certification: requirements, cost and exam format →