🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 12 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

While reviewing Amazon GuardDuty alerts, a security analyst notes repeated port-scan findings against several EC2 instances in a production VPC. The incident response plan requires documenting the evidence, preserving its integrity for audits, and promptly notifying operations and compliance staff. Which solution meets these requirements using AWS-native services?

  • Capture console screenshots of each finding, store the images on a developer laptop, and email them directly to the operations team.

  • Disable GuardDuty to stop additional alerts, then open a Jira ticket summarizing the incident without attaching supporting log data.

  • Post the finding IDs in a shared Slack channel and instruct engineers to investigate further when time permits.

  • Continuously export GuardDuty findings to an encrypted S3 bucket with Object Lock enabled, aggregate them in AWS Security Hub, and trigger an SNS email notification to the operations and compliance lists.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot