Asterrr's Handbook

Domain 2 · Incident response

14% of the exam. Being ready before something goes wrong, then containing, investigating and recovering without destroying the evidence.

Domain 2 questions start after an alarm has fired, or ask what you should have built before it did. The best answer stops the damage first, keeps the evidence intact, and uses a prepared, repeatable path rather than an engineer improvising in the console at 3 a.m.

TaskWhat it's really askingPages
2.1 Build and rehearse the IR planPlaybooks and runbooks, pre-provisioned access and tooling, forensic accounts, game days with FIS and Resilience Hub, automated remediationResponse plan, Automated response
2.2 Respond to security eventsValidating findings, scoping with Detective, containing keys and workloads, capturing forensic artifacts, recovering, root causeValidating findings, Compromised credentials, Compromised workloads, Automated response

Detection itself (turning on GuardDuty, Security Hub, logging) lives in Domain 1. Backups you restore from live in Backup and ransomware protection.

Terminate first, ask later

"Terminate the instance" or "delete the user" feels decisive, but it destroys memory, disk state and the trail you need for root cause. Unless the question says evidence doesn't matter, the right answer isolates and captures before anything is deleted.