AWS Incident Response Framework Quiz

5 questions Pass: 70% +25 pts

Quiz covering Incident Response Planning

AWS Incident Response Framework Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    Which AWS service is primarily used to provide a centralized dashboard for monitoring and managing security alerts and incident response activities across your AWS environment?

  2. 2

    During an incident, you need to isolate an EC2 instance to prevent further data exfiltration while preserving the disk state for forensics. What is the recommended best practice?

  3. 3

    Your team is developing an Incident Response plan. Which AWS service should be used to automate the remediation of a security finding, such as revoking an overly permissive IAM policy?

  4. 4

    An attacker has compromised an IAM user's credentials. Which action should be taken immediately as part of the 'Containment' phase of the incident response lifecycle?

  5. 5

    You are performing a deep forensic analysis on a compromised EC2 instance. The instance is running in a private subnet. How can you securely gain forensic access without altering the original environment's network configuration?