nerdexam
Amazon

SCS-C02 · Question #436

A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company's primary website. The GuardDuty finding received read: Unauthorize

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #436. The question stem and answer options stay visible for context.

Submitted by asante_acc· Mar 6, 2026Threat Detection and Incident Response

Question

A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company's primary website. The GuardDuty finding received read:

UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration. The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company does not operate. The security engineer needs to deny access to the malicious actor. What is the first step the security engineer should take?

Options

  • AOpen the EC2 console and remove any security groups that allow inbound traffic from 0.0.0.0/0.
  • BInstall the AWS Systems Manager Agent on the EC2 instance and run an inventory report.
  • CInstall the Amazon Inspector agent on the host and run an assessment with the CVE rules
  • DOpen the IAM console and revoke all IAM sessions that are associated with the instance profile.

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#GuardDuty#credential exfiltration#IAM session revocation#incident response
Full SCS-C02 Practice