🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company runs a public-facing web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Amazon GuardDuty has generated a high-severity finding that one instance is communicating with a known command-and-control server. According to the NIST incident response lifecycle, what is the MOST appropriate containment step to take immediately?

  • Terminate the Auto Scaling group and redeploy all instances from a hardened Amazon Machine Image (AMI).

  • Detach the affected instance from the Auto Scaling group and associate a security group that blocks all inbound and outbound traffic except to a designated forensic subnet.

  • Publish a post-incident report detailing the compromise and recommended process improvements.

  • Enable AWS Backup on all application Amazon EBS volumes to ensure recent recovery points are available.

ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot