Amazon
SCS-C02 · Question #357
A company's Security Team received an email notification from the Amazon EC2 Abuse team that one or more of the company's Amazon EC2 instances may have been compromised Which combination of actions sh
Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #357. The question stem and answer options stay visible for context.
Submitted by viktor_hu· Mar 6, 2026Incident Response
Question
A company's Security Team received an email notification from the Amazon EC2 Abuse team that one or more of the company's Amazon EC2 instances may have been compromised Which combination of actions should the Security team take to respond to (be current modem? (Choose two.)
Options
- AOpen a support case with the AWS Security team and ask them to remove the malicious code
- BRespond to the notification and list the actions that have been taken to address the incident
- CDelete all IAM users and resources in the account
- DDetach the internet gateway from the VPC remove aft rules that contain 0.0.0.0V0 from the
- EDelete the identified compromised instances and delete any associated resources that the
Unlock SCS-C02 to see the answer
You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Incident Response#EC2 Security#Network Containment#Resource Eradication