AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard

A security engineer is investigating a potential compromise of an Amazon EKS cluster where a malicious container image might have been deployed. The engineer needs to perform live memory forensics on a specific worker node to identify running processes, open network connections, and loaded kernel modules that could indicate compromise. The worker nodes are EC2 instances. Which approach should the engineer take to capture the memory image for forensic analysis?

  1. AStop the EC2 instance and then create an EBS snapshot of the root volume for analysis.
  2. BUtilize the 'create-instance-image' API call to capture a memory snapshot along with the disk image.
  3. CUse AWS Systems Manager to run a memory capture tool directly on the EKS worker node.
  4. DCreate a snapshot of the EC2 instance's root EBS volume and analyze it offline.
Show answer & explanation

Correct answer: C. Use AWS Systems Manager to run a memory capture tool directly on the EKS worker node.

Live memory forensics requires capturing the volatile memory state of a running system. AWS Systems Manager can be used to execute a memory capture tool (like 'LiME' or 'dumpit') on the running EC2 instance (EKS worker node) to obtain a memory dump without stopping or significantly altering the instance's state, which is crucial for live forensics.

Why the other options are wrong

  • A. Stopping the EC2 instance would clear its volatile memory, destroying crucial evidence needed for live memory forensics. An EBS snapshot captures disk state, not memory.
  • B. The 'create-instance-image' API call creates an AMI (disk image) and does not capture the live memory state of the running instance.
  • D. An EBS volume snapshot captures disk state, not live memory. This would miss volatile data critical for live forensics.

Live EC2 Memory Forensics

Live memory forensics involves capturing the volatile memory (RAM) of a running EC2 instance to analyze processes, network connections, and other ephemeral data. This is typically achieved by running a memory capture tool via AWS Systems Manager.

  • Focuses on volatile data not stored on disk.
  • Requires capturing memory while the instance is running.
  • Systems Manager is key for remote execution of capture tools.

Memory trick: Systems Manager is your remote control for live memory evidence collection.

More Domain 1: Incident Response questions