Instiq

1Threat Detection and Incident Response

Practice questions →Glossary →
  • 1.1Threat Detection

    Understand threat detection—GuardDuty, Inspector, Macie, Detective, and IAM Access Analyzer. Find threats, vulnerabilities, and sensitive-data exposure from logs and activity.

  • 1.2Aggregating Findings and Automated Response

    Understand detection-to-response—Security Hub, EventBridge, auto-remediation (Lambda/SSM Automation), and isolation. Centralize findings and respond fast and mechanically.

  • 1.3Incident Response Preparation and Forensics

    Understand IR readiness—playbooks/runbooks, forensics (snapshots/isolation), CloudTrail trails, compromised-credential response, and least-privilege IR roles. Prepare in advance to respond fast and reliably.