CompTIA Cloud+ (CV0-004)SecurityMedium

A cloud security team is investigating a potential compromise. They discovered suspicious API calls originating from an EC2 instance that appear to be exfiltrating data to an external IP address. The instance's security group allows outbound traffic on all ports. The team needs to immediately stop the data exfiltration while preserving the instance's state for forensic analysis. Which of the following is the most appropriate action?

  1. AModify the instance's security group to deny all outbound traffic.
  2. BDetach the Elastic IP address from the EC2 instance.
  3. CCreate a Network Access Control List (NACL) rule to block the external IP address.
  4. DTerminate the EC2 instance to stop all activity immediately.
Show answer & explanation

Correct answer: A. Modify the instance's security group to deny all outbound traffic.

Modifying the security group to deny all outbound traffic will immediately stop any ongoing data exfiltration without altering the instance's state or terminating it, allowing for subsequent forensic analysis. This is a crucial step in the containment phase of incident response.

Why the other options are wrong

  • B. Detaching the Elastic IP might temporarily disrupt outbound traffic if it's the only public IP, but it doesn't guarantee stopping exfiltration if other network paths exist or if the attacker switches IPs.
  • C. Creating a NACL rule for a specific external IP is a reactive measure and might not cover all potential exfiltration paths. Security groups are stateful and more effective for controlling instance-level traffic.
  • D. Terminating the instance would stop the exfiltration but destroy crucial forensic evidence, hindering the investigation.

Incident Response: Containment

The phase of incident response focused on stopping the attack and limiting its damage.

  • Prioritizes immediate damage control.
  • Aims to prevent further compromise.
  • Often involves isolating affected systems.

Memory trick: Cut the network, keep the evidence.

More Security questions