🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

After detecting crypto-mining malware on a Linux EC2 instance that hosts a web API, the incident response team has already quarantined the instance by applying a restrictive security group. According to malware eradication best practices, which next step will most effectively remove the malicious code, minimize downtime, and preserve evidence for later analysis?

  • Remove the quarantine security group, enable Amazon GuardDuty on the account, and continue to monitor the instance for additional malicious behavior before deciding on further action.

  • Use AWS Systems Manager Run Command to install antivirus on the quarantined instance, delete all detected malicious files, and then place the instance back into the production security group.

  • Detach the compromised EBS root volume, attach it to a helper instance to manually remove suspicious binaries, reattach it to the original instance, and restart the server.

  • Create a new instance from a current hardened AMI, update the Auto Scaling group to use it, and snapshot the quarantined instance's EBS volumes for later forensic review before terminating the compromised host.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot