AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A security engineer is investigating a potential compromise of an Amazon EC2 instance. The engineer needs to collect forensic data from the instance, including filesystem integrity checks, running process lists, and network connection states, but must do so without logging into the instance directly via SSH or RDP to avoid further altering the system or leaving traces. Which AWS service can facilitate this remote, agent-based data collection securely?

  1. AAmazon Inspector.
  2. BAmazon GuardDuty.
  3. CAWS CloudTrail.
  4. DAWS Systems Manager (SSM) Agent.
Show answer & explanation

Correct answer: D. AWS Systems Manager (SSM) Agent.

The AWS Systems Manager (SSM) Agent, pre-installed on many EC2 AMIs, allows for remote, secure execution of scripts and commands on instances without needing SSH or RDP. This enables forensic data collection (e.g., running 'lsblk', 'ps -ef', 'netstat -tuln') without direct login, preserving the integrity of the investigation.

Why the other options are wrong

  • A. Amazon Inspector assesses vulnerabilities and compliance, it doesn't execute arbitrary commands for forensic data collection.
  • B. GuardDuty is a threat detection service; it identifies suspicious activity but does not provide tools for collecting forensic data from within an instance.
  • C. CloudTrail logs API calls, not forensic data from within an operating system.

EC2 Remote Forensic Data Collection

AWS Systems Manager (SSM) provides secure, remote management of EC2 instances. Its agent allows security engineers to execute forensic scripts and collect data (e.g., process lists, network states) without direct SSH/RDP login, minimizing impact on potential evidence.

  • SSM Agent is pre-installed on many AMIs.
  • Enables remote command execution without SSH/RDP.
  • Integrates with IAM for granular permissions.

Memory trick: SSM Agent is your ghost in the machine, collecting evidence silently.

More Domain 1: Incident Response questions