nerdexam
Amazon

SCS-C02 · Question #300

A security team is creating a response plan in the event an employee executes unauthorized actions on AWS infrastructure. They want to include steps to determine if the employee's IAM permissions chan

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #300. The question stem and answer options stay visible for context.

Submitted by mateo_ar· Mar 6, 2026Threat Detection and Incident Response

Question

A security team is creating a response plan in the event an employee executes unauthorized actions on AWS infrastructure. They want to include steps to determine if the employee's IAM permissions changed as part of the incident. What steps should the team document in the plan?

Exhibit

SCS-C02 question #300 exhibit

Options

  • AUse AWS Config to examine the employee's IAM permissions prior to the incident and compare
  • BUse Made to examine the employee's IAM permissions prior to the incident and compare them to
  • CUse CloudTrail to examine the employee's IAM permissions prior to the incident and compare
  • DUse Trusted Advisor to examine the employee's IAM permissions prior to the incident and

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Config#IAM permissions#incident response#change tracking
Full SCS-C02 Practice