AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A security engineer is investigating a potential compromise of an Amazon EC2 instance. Initial alerts indicate unusual outbound network traffic to a known malicious IP address. The engineer needs to quickly isolate the compromised instance without disrupting other services while preserving its state for forensic analysis. Which AWS service and action should the engineer take first?

  1. ADetach the instance's Elastic Network Interface (ENI) and attach it to a new, isolated VPC.
  2. BModify the security groups associated with the EC2 instance to deny all inbound and outbound traffic.
  3. CTerminate the EC2 instance immediately to prevent further damage and then restore from a backup.
  4. DStop the EC2 instance and create an Amazon Machine Image (AMI) from it for analysis.
Show answer & explanation

Correct answer: B. Modify the security groups associated with the EC2 instance to deny all inbound and outbound traffic.

Modifying the security groups to deny all traffic is the quickest and most effective way to isolate a compromised EC2 instance without altering its state, which is crucial for forensic analysis. This action immediately stops further malicious activity while allowing investigators to access the instance if needed via other channels.

Why the other options are wrong

  • A. Detaching and reattaching an ENI is more complex and disruptive, potentially changing network configuration and making forensic analysis harder. It also doesn't immediately stop active connections.
  • C. Terminating the instance destroys crucial evidence for forensic analysis and should only be a last resort after all necessary evidence is collected or if the risk is extremely high and uncontainable otherwise.
  • D. Stopping the instance will preserve its state but might disrupt ongoing forensic collection if not carefully managed. It also doesn't immediately stop active network connections until the instance is fully stopped.

EC2 Instance Isolation

The process of preventing a potentially compromised Amazon EC2 instance from communicating with other systems while preserving its state for investigation.

  • Crucial for containing security incidents.
  • Network-level isolation is often the first step.
  • Preservation of state is vital for forensic analysis.

Memory trick: Security Groups are your first fence for a compromised EC2.

More Domain 1: Incident Response questions