🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security analyst must preserve disk evidence from a running Amazon EC2 instance that is suspected of hosting malware. According to forensic best practices, which initial action will BEST capture the data while maintaining the chain of custody and preventing accidental modification of the original evidence?

  • Use the no-reboot option to create an Amazon Machine Image (AMI) of the instance, then terminate the original instance to stop changes.

  • Stop the instance, detach all EBS volumes, and attach them to a separate forensic EC2 instance in the same account for analysis.

  • Install an up-to-date antivirus engine on the instance and perform a full malware scan before copying suspect files to Amazon S3.

  • Create an Amazon EBS snapshot of every attached volume from the AWS console and apply evidence tags before any other action.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot