AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseHard

A DevOps team needs to implement an automated system to perform post-incident analysis on EC2 instances. This involves collecting forensic data (e.g., memory dumps, disk images, log files) from a potentially compromised instance, storing it securely, and then isolating the instance. The process must be initiated on demand and ensure data integrity. Which combination of AWS services should be used?

  1. AAWS Systems Manager Automation documents, Amazon S3, and EC2 Stop/Terminate actions.
  2. BAmazon CloudWatch Logs, Amazon SNS, and manual SSH access for data collection.
  3. CAWS CloudTrail, Amazon EventBridge, and AWS Lambda to trigger data collection.
  4. DAWS Security Hub, AWS GuardDuty, and Amazon Inspector for threat detection and reporting.
Show answer & explanation

Correct answer: A. AWS Systems Manager Automation documents, Amazon S3, and EC2 Stop/Terminate actions.

AWS Systems Manager Automation documents can orchestrate complex workflows, including creating snapshots (for disk images), running scripts to collect memory dumps and logs, and then storing them in S3. The Automation document can also include steps to stop or terminate the instance for isolation. This provides an on-demand, auditable, and automated way to collect forensic data and isolate the instance.

Why the other options are wrong

  • B. Manual SSH access for data collection is not automated, scalable, or consistent, and SNS is for notifications, not orchestrating data collection and isolation.
  • C. CloudTrail, EventBridge, and Lambda can trigger actions, but Automation documents are better suited for the multi-step, complex orchestration required for forensic data collection and instance isolation.
  • D. Security Hub, GuardDuty, and Inspector are for threat detection and vulnerability assessment, not for automated forensic data collection and instance isolation.

Automated Forensic Data Collection with SSM Automation

This pattern uses AWS Systems Manager Automation documents to orchestrate the automated collection of forensic artifacts (snapshots, memory dumps, logs) from EC2 instances and securely store them, followed by instance isolation.

  • Orchestrates complex incident response workflows.
  • Automates data collection from EC2 instances.
  • Ensures secure storage and instance isolation.

Memory trick: SSM Automation takes the lead, collects the data, plants the seed, then isolates the instance, a crucial deed.

More Incident and Event Response questions