exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 97 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 97
Topic #: 1
[All AWS Certified Security - Specialty Questions]

An organization receives an alert that indicates that an EC2 instance behind an ELB Classic Load Balancer has been compromised.
What techniques will limit lateral movement and allow evidence gathering?

  • A. Remove the instance from the load balancer and terminate it.
  • B. Remove the instance from the load balancer, and shut down access to the instance by tightening the security group.
  • C. Reboot the instance and check for any Amazon CloudWatch alarms.
  • D. Stop the instance and make a snapshot of the root EBS volume.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mojoa
Highly Voted 3 years, 7 months ago
I think B is the best answer. Page 34 https://d1.awsstatic.com/whitepapers/aws_security_incident_response.pdf No mention of stopping the EC2 instance. Just isolation so information can be gathered. It is possible to do snapshot while the instance is running.
upvoted 26 times
s3an
3 years, 7 months ago
yes you're right (B is best). Page 36 shows option B and D are both correct, but option B will allow more evidences (volatile evidence ....such as memory or network traffic) to be gathered. Also the question says "limit lateral movement" and not completely stop movement or access.
upvoted 13 times
...
...
josellama2000
Highly Voted 3 years, 7 months ago
Agree. Answer is B. Shutting down the instance will change the state of it and more probable destroy transient evidence. The snapshot must be done while the instance is on.
upvoted 8 times
...
a1234321606
Most Recent 5 months, 3 weeks ago
Selected Answer: D
Ans is D, since B cannot interrupt the connection and doesn't mention how to gather evidence https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/security-group-connection-tracking.html
upvoted 1 times
...
OCHT
1 year, 10 months ago
Selected Answer: B
Removing the compromised instance from the load balancer prevents further traffic from reaching it. Adjusting the security group to shut down access helps to limit potential lateral movement, preventing the attacker from reaching other resources in your network. It also allows time for a detailed investigation to take place without the risk of ongoing malicious activity. Please note, creating a snapshot of the EBS volume (option D) can be a part of an incident response process for deeper forensic analysis. However, the question specifically asked about techniques to "limit lateral movement and allow evidence gathering" without implying a detailed forensic analysis, thus making option B more suitable.
upvoted 3 times
...
ITGURU51
1 year, 11 months ago
The questions specially states that we need to perform a cyber threat investigation. However once the endpoint is turned off or restarted the opportunity for forensic analysis will be taken away. B limits the lateral movement and still allows the security engineer to investigate the situation.
upvoted 1 times
...
Dmosh
2 years ago
Selected Answer: B
ANS: B
upvoted 1 times
...
VijiTu
2 years, 7 months ago
The approach is to isolate the ec2 instance and restrict the security group for the forensic analysis so B is the answer
upvoted 1 times
...
pmjcr
3 years, 5 months ago
My anwser is D. It states to limit lateral movement so security groups will do nothing as they will not block any outbound traffic. I know memory dump is always best to gather all data for inspection, but the requirement is clear. "limit lateral movement" so we keep to the requirement while still be able to investigate the snapshot of the EBS.
upvoted 2 times
ryan112277
3 years, 5 months ago
You can restrict outbound traffic using security groups
upvoted 2 times
...
dumma
3 years, 5 months ago
D is wrong because you need snapshot of all, it only says snapshot of root volume. Correct answer is B.
upvoted 2 times
...
...
sanjaym
3 years, 5 months ago
Ans: B 100%
upvoted 2 times
...
ChinkSantana
3 years, 5 months ago
B is correct Here. Question ask 2 requirements. Stop Bilateral movement and Evidence gathering. A shutdown system wont help much in evidence/forensic investigations.
upvoted 1 times
...
argol
3 years, 6 months ago
limit lateral movement "B" is the answer
upvoted 1 times
...
Sitender
3 years, 6 months ago
B is more appropriate.............D (if you shut down, content of memory or swap file) will be gone, which hold important info.
upvoted 3 times
...
od87
3 years, 6 months ago
C is correct, not sure anyone has faced a security incident before. i work regularly with security team....you NEVER reboot / Shutdown the instance in question while evidence gathering like collecting logs etc. as that affects evidence gathering you remove it from LB and disable all services so it is not in production.
upvoted 2 times
od87
3 years, 6 months ago
i meant B.
upvoted 4 times
...
...
NANDY666
3 years, 6 months ago
B is Correct
upvoted 1 times
...
Melymel
3 years, 6 months ago
it's D - lateral movement means potential risk to the rest of the environment. Offline investigation (where instance is shut down) means that it can no longer affect the rest of the environment. Snapshot of EBS volume can be used to create new volumes that can be mounted onto a forensic EC2 instance for deep analysis offline.
upvoted 5 times
...
shooricg
3 years, 6 months ago
It has to be C. D limits what can be done to investigate. C, is on point.
upvoted 1 times
...
devjava
3 years, 6 months ago
Ans > B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago