AWS Incident Response Framework Quiz

5 questions Pass: 70% +25 pts

Quiz covering Incident Response Planning

AWS Incident Response Framework Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which AWS service is primarily used to collect and store logs for security auditing and forensic analysis during an incident?

  2. 2

    During the 'Containment' phase of an incident, which action is considered a best practice for an EC2 instance suspected of being compromised?

  3. 3

    Which AWS service would you use to automate the response to a detected security threat, such as automatically revoking an IAM user's credentials?

  4. 4

    When performing forensic analysis on an EC2 instance, why is it recommended to create a snapshot of the EBS volume rather than imaging the live disk?

  5. 5

    You have identified an unauthorized IAM role modification. According to the AWS Shared Responsibility Model, which component of the incident response process is entirely the customer's responsibility?