ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
After eradicating malware from an EC2-based application, the incident response team launches a fresh instance from a known-good, encrypted AMI backup. The RTO is 45 minutes and the business is pressuring to return service. According to the recovery phase of the incident response lifecycle, what should the team do next before placing the instance behind the production load balancer?
Rotate all IAM access keys used by the application and update the entries in AWS Secrets Manager.
Connect the instance to the production Auto Scaling group immediately and monitor Amazon CloudWatch for anomalies.
Archive forensic EBS snapshots of the compromised instance to Amazon S3 Glacier Deep Archive for long-term retention.
Execute automated security and functional validation tests in a staging VPC to confirm the instance's integrity.
During the recovery phase, systems restored from backup must be validated to ensure they are free of compromise and operate as expected before returning them to production. Running automated security scans and functional regression tests in an isolated or staging environment confirms the integrity and reliability of the rebuilt instance. Simply re-introducing the host and monitoring it, rotating credentials, or archiving forensic evidence are valuable activities, but they do not satisfy the required system validation step that must precede production use.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an AMI backup in AWS?
Open an interactive chat with Bash
What is a staging VPC, and why is it used?
Open an interactive chat with Bash
What is the incident response lifecycle's recovery phase?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .