AWS Certified Security – SpecialtyDomain 1: Incident ResponseEasy

A security engineer is investigating a potential compromise of an Amazon EC2 instance within a production VPC. The instance is suspected of communicating with a known command-and-control (C2) server. The engineer needs to immediately block all inbound and outbound traffic to and from this specific EC2 instance without affecting other instances in the same security group or subnet, to contain the threat and prevent further data exfiltration or lateral movement. Which AWS service or feature should the engineer use to achieve this containment effectively and with the highest granularity?

  1. AUpdate the route table of the subnet to blackhole traffic destined for the instance's IP address.
  2. BApply a new, restrictive security group to the compromised EC2 instance, revoking all inbound and outbound rules.
  3. CModify the Network Access Control List (NACL) associated with the subnet to deny traffic to and from the instance's IP address.
  4. DDetach the Elastic Network Interface (ENI) from the compromised EC2 instance.
Show answer & explanation

Correct answer: B. Apply a new, restrictive security group to the compromised EC2 instance, revoking all inbound and outbound rules.

Applying a new, restrictive security group directly to the compromised EC2 instance offers the most granular and immediate containment without impacting other resources. Security groups operate at the instance level, allowing for precise control.

Why the other options are wrong

  • A. Modifying route tables for a single instance's IP within a subnet is not a standard or efficient way to isolate a single EC2 instance and could lead to routing complexities.
  • C. NACLs operate at the subnet level and would affect all instances within that subnet, not just the compromised one.
  • D. Detaching the ENI would isolate the instance but is a more disruptive action that might not be necessary for containment and could hinder forensic collection later.

EC2 Instance Isolation with Security Groups

Security groups act as a virtual firewall for EC2 instances, controlling inbound and outbound traffic. They are stateful and operate at the instance level, making them ideal for granular instance isolation during an incident.

  • Operate at the instance level, not subnet.
  • Are stateful: return traffic is automatically allowed.
  • Can be modified dynamically to restrict traffic instantly.

Memory trick: Security Groups are like personal bodyguards for each EC2 instance.

More Domain 1: Incident Response questions