🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

An information security team manages Windows Server 2019 instances in an Amazon EC2 Auto Scaling group that hosts an internal web application. Recently, incident responders observed repeated outbound command-and-control connections and malicious PowerShell commands executing only in memory; no suspicious binaries were found on disk. To most effectively detect and contain this fileless malware while minimizing ongoing operational effort, which action should the team take?

  • Use AWS Systems Manager Automation to run nightly full-disk signature-based antivirus scans on every instance.

  • Install a host-based endpoint detection and response (EDR) agent that applies behavior analytics and memory scanning to detect and quarantine suspicious processes.

  • Activate Amazon GuardDuty to alert on unusual VPC Flow Log and DNS activity and automatically isolate any flagged instance.

  • Enable deep packet inspection on the VPC network firewall and block all outbound traffic that is not destined for approved domains.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot