2.0 Incident Response SCS-C03 Practice Quiz

84 exam-style questions covering 14% of the SCS-C03 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the AWS Certified Security Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A GuardDuty finding indicates possible EC2 credential exfiltration. The security team wants a repeatable plan that analysts can execute consistently. What should the runbook define first?
  • A. Triage steps, severity criteria, affected-resource identification, containment actions, and evidence preservation
  • B. Immediate termination of every EC2 instance in the account
  • C. Only a link to the GuardDuty console with no response steps
  • D. A request to disable CloudTrail during investigation

A useful incident runbook starts by turning the finding into a scoped, prioritized workflow that preserves evidence before destructive changes occur.

A team uses Systems Manager OpsCenter for incident work. What should a security incident response plan specify?
  • A. How findings create OpsItems, required context fields, assignment, escalation, and linked automation documents
  • B. Use OpsCenter only as a generic bookmark folder
  • C. Place production credentials in OpsItem descriptions
  • D. Create OpsItems manually only after all remediation is complete

OpsCenter is most effective when incident intake, ownership, context, and automation links are defined before incidents occur.

A company has separate playbooks for public S3 bucket exposure, compromised IAM credentials, and suspicious container runtime activity. What should be standardized across all playbooks?
  • A. The same containment command for every incident type
  • B. Roles, severity model, communication path, evidence handling, escalation triggers, and closure criteria
  • C. A requirement to wait for business hours before any response
  • D. A policy to delete raw evidence after summary writing

Common response structure keeps incident execution consistent while allowing technical steps to differ by incident type.

A runbook for AI application abuse must address prompt injection and unsafe output attempts. What should it include?
  • A. Store every user prompt publicly for community analysis
  • B. Detection inputs, guardrail outcomes, abuse-scoping steps, model access review, and safe evidence handling
  • C. Treat all model refusals as successful attacks
  • D. Disable all application authentication to reproduce abuse

GenAI incident response needs application-specific evidence, control outcomes, and user or identity scope without overcollecting sensitive prompts.

A team wants every high-severity incident runbook to support rapid handoff between shifts. Which section is essential?
  • A. A blank template that responders fill in after closure
  • B. Current state summary, completed actions, open hypotheses, evidence locations, and next decisions
  • C. Only a list of AWS service names with no actions
  • D. A requirement that the original responder stay online indefinitely

Shift handoff needs operational context that prevents repeated work and preserves decision continuity.

A runbook for suspected IAM key compromise must support fast containment without losing attribution. Which step belongs in the runbook?
  • A. Delete the IAM user and all CloudTrail records immediately
  • B. Rotate unrelated KMS keys before confirming the principal's actions
  • C. Deactivate the access key, preserve CloudTrail activity, and investigate recent API calls by the principal
  • D. Open administrator access to all responders by default

Disabling the key limits further use while CloudTrail evidence identifies scope, actions, and resources affected.

A regulated organization wants runbooks that auditors can review. What design requirement matters most?
  • A. Runbooks edited only in an untracked chat thread
  • B. A plan that depends entirely on one engineer's memory
  • C. Version-controlled runbooks with approvals, test history, and mapped evidence requirements
  • D. A single emergency role with no logging requirement

Auditable runbooks need change history, governance, and proof that procedures are tested and aligned to evidence needs.

A security team wants response plans for ransomware-like activity in an S3 data lake. Which runbook element is most important?
  • A. Disable S3 Versioning after the first suspicious delete
  • B. Make the bucket public so external analysts can inspect it quickly
  • C. Delete lifecycle and access logs to reduce storage charges
  • D. Steps to isolate write paths, preserve object versions, review access logs, and validate clean recovery points

S3 ransomware response depends on stopping destructive writes, retaining object history, and recovering from trusted versions or backups.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/aws-security-specialty/incident-response/

<a href="https://quizbuffet.com/aws-security-specialty/incident-response/">AWS Security Specialty Incident Response practice quiz on QuizBuffet</a>

Other SCS-C03 Domains

← Back to SCS-C03 practice test overview

Questions are written against the published SCS-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.