Skip to content

Incident Response Questions

Practice questions for Incident Response topic in AWS Certified Security - Specialty. 28 questions covering this domain.

28 questions8 easy12 medium8 hard
Q1
medium

A team wants a vulnerability management service that automatically discovers and continuously rescans eligible resources when packages change, patches...

Q2
hard

An Amazon Inspector finding is based on a vulnerability that is exploitable over the network, but the affected EC2 instance has no open network path t...

Q3
easy

A company wants administrators to connect to EC2 instances for incident response without opening inbound SSH or RDP ports, maintaining bastion hosts, ...

Q4
medium

A security team needs near-real-time routing of Amazon Inspector findings to automated remediation targets such as Lambda functions or SNS topics. Whi...

Q5
medium

A company wants to standardize patching across all AWS accounts and Regions in its organization by using a recommended centralized configuration metho...

Q6
easy

A security analyst needs to investigate multiple related suspicious activities tied to a high-severity GuardDuty finding and quickly understand the ro...

Q7
hard

A response team must access a private service running on a managed node during an incident, but the organization does not want to open inbound ports t...

Q8
medium

A security team needs to ensure backups used for ransomware recovery cannot be deleted or shortened by any user, including the AWS account root user, ...

Q9
hard

A team wants to automate forensic disk capture of a suspicious EC2 instance, copy the image to an isolated forensics account, and trigger this flow fr...

Q10
hard

After a credential compromise, AWS guidance directs the team to perform a specific sequence of credential containment actions for the affected IAM rol...

Q11
medium

A security engineer must immediately quarantine a compromised EC2 instance from the network while preserving its data for forensic analysis. Which app...

Q12
easy

Which AWS service can run prebuilt or custom runbook documents to automate routine response tasks such as isolating an EC2 instance or rotating a cred...

Q13
easy

Which AWS service provides response plans, on-call schedules, runbooks, escalation, and chat-based collaboration during incidents?

Q14
medium

An incident responder must invalidate all currently issued temporary credentials for an IAM role that was assumed by a compromised workload. Which IAM...

Q15
hard

A security team discovers an active S3 data exfiltration attack occurring through a compromised IAM access key. They need to immediately stop the exfi...

Q16
medium

A forensics team needs to capture a memory dump and volatile state from a running EC2 instance during an active incident without terminating the insta...

Q17
medium

An incident team needs to automatically trigger a response workflow when Amazon GuardDuty generates a high-severity finding, including sending a notif...

Q18
hard

An incident response team needs to determine whether a suspicious IAM role that was used two days ago had any resource-level permissions to access Ama...

Q19
easy

A security engineer needs to quarantine a compromised Lambda function that is processing sensitive records. Which combination of actions minimizes the...

Q20
easy

A security team wants to test the resilience of its incident response plan by simulating a sudden termination of EC2 instances in a production environ...

Sign in to see all 28 questions

Create a free account to browse all questions — completely free during our launch phase.