🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 11 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company hosts its e-commerce application entirely on AWS. After a breach in which stolen long-lived IAM access keys were used to copy sensitive objects from an S3 bucket, the incident response team has completed containment, eradication, and recovery. As the practitioner moves into the post-incident activities phase, which action best aligns with industry-standard incident response guidance for lessons learned and continuous improvement?

  • Immediately reinstate the affected IAM user's original permissions to avoid disrupting business operations.

  • Document the full incident timeline, identify root causes and control gaps, and update incident response runbooks before formally closing the case.

  • Disable S3 versioning on the bucket to reduce storage costs associated with multiple object copies.

  • Purge all evidence related to the breach and disable Amazon CloudTrail to minimize future log-storage costs.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot