AWS Certified Security – SpecialtyDomain 1: Incident ResponseHard

A security engineer needs to analyze the full network traffic (packet capture) of a suspected compromised EC2 instance without directly logging into it or installing agents, to avoid altering the evidence. The analysis requires deep inspection of network protocols and payloads. Which AWS service combination provides the capability to capture and analyze this traffic?

  1. AVPC Flow Logs and Amazon Athena.
  2. BAmazon GuardDuty for identifying anomalous network activity.
  3. CTraffic Mirroring to an EC2 instance running network analysis tools.
  4. DAWS Network Firewall with logging enabled to Amazon S3.
Show answer & explanation

Correct answer: C. Traffic Mirroring to an EC2 instance running network analysis tools.

Traffic Mirroring allows you to copy network traffic from an ENI of a source instance to a target ENI (e.g., on a forensic EC2 instance). This enables full packet capture and deep inspection using tools like Wireshark or tcpdump without impacting the compromised instance or requiring agent installation.

Why the other options are wrong

  • A. VPC Flow Logs provide metadata (source/destination IP, port, protocol, bytes) but not the full packet payload, which is required for deep protocol and payload inspection.
  • B. Amazon GuardDuty detects anomalous network activity and generates findings, but it does not capture raw network packets for forensic analysis. It's a detection service, not a capture service.
  • D. AWS Network Firewall can inspect and filter traffic, and its logs provide detailed information, but it does not provide raw packet capture for deep forensic analysis of protocols and payloads.

VPC Traffic Mirroring for Forensics

A VPC feature that allows copying network traffic from an Elastic Network Interface (ENI) to a target ENI, enabling full packet capture and deep forensic analysis without impacting the source instance.

  • Provides full packet capture (payloads).
  • Non-intrusive to the source instance.
  • Traffic sent to a dedicated analysis instance.
  • Ideal for deep network protocol inspection.

Memory trick: Traffic Mirroring: your forensic traffic cop, copying everything.

More Domain 1: Incident Response questions