nerdexam
Amazon

SCS-C02 · Question #38

A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the accou

The correct answer is B. Log in to the AWS account by using read-only credentials. Review the GuardDuty finding to. https://aws.amazon.com/blogs/security/how-you-can-use-amazon-guardduty-to-detect- suspicious-activity-within-your-aws- account/#:~:text=Start%20an%20investigation%20with%20Amazon%20Detective

Submitted by katya_ua· Mar 6, 2026Incident Response

Question

A company has an AWS account that hosts a production application. The company receives an email notification that Amazon GuardDuty has detected an Impact:IAMUser/AnomalousBehavior finding in the account. A security engineer needs to run the investigation playbook for this security incident and must collect and analyze the information without affecting the application. Which solution will meet these requirements MOST quickly?

Options

  • ALog in to the AWS account by using read-only credentials. Review the GuardDuty finding for
  • BLog in to the AWS account by using read-only credentials. Review the GuardDuty finding to
  • CLog in to the AWS account by using administrator credentials. Review the GuardDuty finding for
  • DLog in to the AWS account by using read-only credentials. Review the GuardDuty finding to

How the community answered

(65 responses)
  • A
    5% (3)
  • B
    85% (55)
  • C
    2% (1)
  • D
    9% (6)

Explanation

https://aws.amazon.com/blogs/security/how-you-can-use-amazon-guardduty-to-detect- suspicious-activity-within-your-aws- account/#:~:text=Start%20an%20investigation%20with%20Amazon%20Detective

Topics

#GuardDuty findings#IAM anomalous behavior#incident response playbook#read-only investigation

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice