SCS-C02 · Question #32
SCS-C02 Question #32: Real Exam Question with Answer & Explanation
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #32. The question stem and answer options stay visible for context.
Question
A security engineer needs to develop a process to investigate and respond to potential security events on a company's Amazon EC2 instances. All the EC2 instances are backed by Amazon Elastic Block Store (Amazon EBS). The company uses AWS Systems Manager to manage all the EC2 instances and has installed Systems Manager Agent (SSM Agent) on all the EC2 instances. The process that the security engineer is developing must comply with AWS security best practices and must meet the following requirements: - A compromised EC2 instance's volatile memory and non-volatile memory must be preserved for forensic purposes. - A compromised EC2 instance's metadata must be updated with corresponding incident ticket information. - A compromised EC2 instance must remain online during the investigation but must be isolated to prevent the spread of malware. - Any investigative activity during the collection of volatile data must be captured as part of the process. Which combination of steps should the security engineer take to meet these requirements with the LEAST operational overhead? (Choose three.)
Options
- AGather any relevant metadata for the compromised EC2 instance. Enable termination protection.
- BGather any relevant metadata for the compromised EC2 instance. Enable termination protection.
- CUse Systems Manager Run Command to invoke scripts that collect volatile data.
- DEstablish a Linux SSH or Windows Remote Desktop Protocol (RDP) session to the compromised
- ECreate a snapshot of the compromised EC2 instance's EBS volume for follow-up investigations.
- FCreate a Systems Manager State Manager association to generate an EBS volume snapshot of
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.