Domain 2 · Incident response
14% of the exam. Being ready before something goes wrong, then containing, investigating and recovering without destroying the evidence.
Domain 2 questions start after an alarm has fired, or ask what you should have built before it did. The best answer stops the damage first, keeps the evidence intact, and uses a prepared, repeatable path rather than an engineer improvising in the console at 3 a.m.
| Task | What it's really asking | Pages |
|---|---|---|
| 2.1 Build and rehearse the IR plan | Playbooks and runbooks, pre-provisioned access and tooling, forensic accounts, game days with FIS and Resilience Hub, automated remediation | Response plan, Automated response |
| 2.2 Respond to security events | Validating findings, scoping with Detective, containing keys and workloads, capturing forensic artifacts, recovering, root cause | Validating findings, Compromised credentials, Compromised workloads, Automated response |
Detection itself (turning on GuardDuty, Security Hub, logging) lives in Domain 1. Backups you restore from live in Backup and ransomware protection.
Terminate first, ask later
"Terminate the instance" or "delete the user" feels decisive, but it destroys memory, disk state and the trail you need for root cause. Unless the question says evidence doesn't matter, the right answer isolates and captures before anything is deleted.
Troubleshooting monitoring
Finding why logs, alarms and alerts go missing, from the CloudWatch agent and Lambda or API Gateway logging to trail and bucket policies, KMS key policies on log destinations, and EventBridge rules that never fire.
Designing and testing a response plan
The incident response lifecycle on AWS, playbooks and runbooks, pre-provisioned access and a forensics account, AWS Security Incident Response, and testing the plan with FIS, Resilience Hub and ARC.