Your SOC detects repeated anomalous API calls from a cloud IAM user tied to a compromised workstation. The team wants to contain the cloud access before investigating the API logs. Which action best balances immediate containment with forensic visibility?
Select an answer to reveal the explanation.
Short Explanation
Think of containment like putting a suspect in a holding cell: stop the movement, keep the evidence intact. Disable the cloud user now, but don't wipe the trail—you need the account record and API logs to reconstruct what happened. If you delete or scrub first, you've stopped the attacker and blinded yourself.
Full Explanation
Containment in incident response is a sequencing problem: you must reduce attacker capability while preserving the evidence needed for reconstruction. In a cloud identity incident, disabling the compromised IAM user stops new API requests from succeeding, while retaining the user object, access key metadata, and API logs preserves the audit trail. This supports attribution, lateral movement analysis, and scoping of affected resources. Deleting the user or purging access keys may remove identifiers, key associations, and historical audit context that are required to establish who performed the actions and when. Rotating keys while leaving the account active can reduce one credential path, but it does not reliably terminate existing sessions or active access, and it may obscure the incident timeline if the account remains usable. Disabling access keys but deleting historical API logs directly destroys forensic visibility, making it impossible to validate scope, persistence, or blast radius. Exam caveat: when the question asks for containment plus forensic visibility, prefer reversible, evidence-preserving isolation over destructive cleanup. Operational check: before changing the cloud user, capture the user's identifier, attached policies, access key metadata, and recent API log entries into the case evidence repository, then disable access and verify the account cannot authenticate.