AWS Certified Security – SpecialtyDomain 1: Incident ResponseMedium

A financial services company uses AWS for its critical applications. A recent security alert from Amazon GuardDuty indicates a 'Backdoor:EC2/C&CActivity.B' finding on an EC2 instance, suggesting communication with a known command and control server. The security team needs to immediately isolate the compromised instance from the network while preserving its state for forensic analysis. Which AWS security service and action should be taken first to achieve this?

  1. AModify the security groups associated with the EC2 instance to deny all inbound and outbound traffic.
  2. BTerminate the EC2 instance to prevent further malicious activity and then restore from a recent AMI.
  3. CDetach the Elastic Network Interface (ENI) from the compromised EC2 instance.
  4. DStop the EC2 instance to prevent further communication and take a snapshot of its EBS volume.
Show answer & explanation

Correct answer: A. Modify the security groups associated with the EC2 instance to deny all inbound and outbound traffic.

Modifying the security groups to deny all traffic is the most immediate and effective way to isolate a compromised EC2 instance without altering its state, which is crucial for forensic analysis. It prevents further C2 communication while keeping the instance running.

Why the other options are wrong

  • B. Terminating the instance destroys evidence and prevents forensic analysis on the live system.
  • C. Detaching the ENI will isolate the instance but might disrupt certain forensic tools or processes that expect network connectivity, even if restricted. Modifying security groups is generally preferred for isolation that maintains instance state.
  • D. Stopping the instance changes its state and can wipe volatile memory, which is critical for some forensic investigations. It's also not as immediate as a security group change.

EC2 Network Isolation

The process of immediately restricting network access to a potentially compromised EC2 instance to prevent further malicious activity while preserving its state for investigation.

  • Primary method is security group modification.
  • Aims to block all ingress/egress traffic.
  • Preserves instance state for forensic analysis.

Memory trick: Security Groups are your first line of defense for network isolation.

More Domain 1: Incident Response questions