A security engineer needs to establish a secure and isolated environment for forensic analysis of a compromised EC2 instance. The forensic workstation needs to access the compromised instance's EBS volumes without any network connectivity to the internet or other production resources, and all actions must be logged. Which combination of AWS services and features should be used to create this forensic environment?
- ACreate a new isolated VPC with no internet gateway, launch a forensic EC2 instance, attach the compromised EBS volume, and use a VPC endpoint for S3 for tool storage.
- BAttach the compromised EBS volume to an existing EC2 instance in a private subnet and access it via AWS Systems Manager Session Manager.
- CUse AWS CodeBuild to run forensic tools on the compromised EBS volume directly.
- DLaunch a new EC2 instance in a dedicated VPC, attach the compromised EBS volume, and access via SSH with a public IP.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a new isolated VPC with no internet gateway, launch a forensic EC2 instance, attach the compromised EBS volume, and use a VPC endpoint for S3 for tool storage.
Creating a new, isolated VPC with no internet gateway ensures network isolation. Launching a forensic instance within this VPC and attaching the compromised EBS volume allows for offline analysis. Using a VPC endpoint for S3 provides secure, private access to S3 for forensic tools and evidence storage without exposing the environment to the internet.
Why the other options are wrong
- B. Attaching to an existing EC2 instance might compromise the existing instance or expose the forensic analysis to other resources in that subnet. While Session Manager provides secure access, the overall environment might not be sufficiently isolated without a dedicated VPC.
- C. AWS CodeBuild is a continuous integration service for building and testing code, not designed for interactive forensic analysis of EBS volumes.
- D. Using a public IP and SSH introduces network exposure, violating the isolation requirement. A dedicated VPC is good, but the public IP undermines security.
AWS Forensic Environment Setup
A secure AWS forensic environment involves creating a highly isolated VPC (no internet gateway) for analysis. This prevents contamination and ensures evidence integrity, with controlled access to necessary services like S3 via VPC endpoints.
- Requires strict network isolation (dedicated VPC, no internet gateway).
- Compromised volumes are attached to a clean forensic instance.
- VPC endpoints provide secure access to AWS services (e.g., S3) without public internet.
Memory trick: Build a secure sandbox for your forensics, locked away from the internet.