AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard

A security team needs to establish a dedicated, isolated environment within AWS for conducting forensic analysis of compromised resources. This environment must ensure that forensic tools and collected evidence cannot communicate with production networks or the internet, except for strictly controlled outbound access for updates. Which combination of AWS networking components should be used to build this highly isolated forensic environment?

  1. AA new VPC with only private subnets, a NAT Gateway for outbound access, and a strict NACL.
  2. BA new VPC with a public subnet, an internet gateway, and tightly configured security groups.
  3. CA new VPC with a public subnet, an internet gateway, and a proxy server for all outbound traffic.
  4. DA new VPC with only private subnets, no internet gateway, and a VPC endpoint for AWS service access.
Show answer & explanation

Correct answer: D. A new VPC with only private subnets, no internet gateway, and a VPC endpoint for AWS service access.

A new VPC with only private subnets and no Internet Gateway ensures maximum isolation from the internet. Using VPC endpoints (e.g., for S3, EC2 APIs) allows forensic tools to interact with necessary AWS services without traversing the public internet, satisfying the 'strictly controlled outbound access' requirement.

Why the other options are wrong

  • A. While private subnets and NACLs are good, a NAT Gateway provides general outbound internet access, which is less controlled than VPC endpoints for specific AWS services. The requirement specifies 'strictly controlled outbound access for updates' which VPC endpoints align better with for AWS services.
  • B. A public subnet and internet gateway expose the environment to the internet, which is contrary to the requirement for high isolation.
  • C. A public subnet and internet gateway are not suitable for a highly isolated environment. While a proxy can control outbound traffic, it still relies on an internet gateway for initial connectivity, which is less secure than no internet gateway at all.

Isolated Forensic VPC

An AWS VPC specifically designed with high network isolation (private subnets, no internet gateway, VPC endpoints) to securely house forensic analysis tools and evidence, preventing unauthorized egress or ingress.

  • Uses private subnets exclusively.
  • No Internet Gateway for outbound internet access.
  • VPC Endpoints for controlled AWS service communication.
  • Ensures evidence integrity and isolation.

Memory trick: Private subnets and VPC endpoints: your forensic no-fly zone.

More Domain 1: Incident Response questions