🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

During an overnight shift you receive an Amazon GuardDuty finding that a production Amazon EC2 instance is repeatedly contacting a known command-and-control domain. As the on-call first responder, you must preserve evidence while stopping further attacker communication without powering off the instance. Which immediate action best satisfies these requirements?

  • Terminate the compromised instance and launch a replacement from a known-good Amazon Machine Image (AMI).

  • Stop the EC2 instance to halt the malicious processes and freeze its state.

  • Immediately patch the operating system and rotate all IAM credentials used by the instance.

  • Attach a security group that contains no inbound or outbound rules, completely isolating the instance from the network while it stays powered on.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot