A security engineer received an Amazon GuardDuty alert indicating a finding involving the Amazon EC2 instance that hosts the company's primary website. The
GuardDuty finding received read:
UnauthorizedAccess:IAMUser/InstanceCredentialExfiltration.
The security engineer confirmed that a malicious actor used API access keys intended for the EC2 instance from a country where the company does not operate.
The security engineer needs to deny access to the malicious actor.
What is the first step the security engineer should take?
DayQuil
Highly Voted 3 years, 9 months agoDaniel76
3 years, 8 months agoRaphaello
Most Recent 1 year, 4 months agoEricZhang
1 year, 8 months agoOCHT
2 years, 1 month agoITGURU51
2 years, 2 months agoluk3k0
2 years, 4 months agoarpgaur
2 years, 5 months agodcasabona
2 years, 11 months agoJonfernz
3 years, 1 month agoJonfernz
3 years, 1 month agohk436
3 years, 8 months agoskipbaylessfor3
3 years, 8 months agoJoanale
3 years, 8 months agoskipbaylessfor3
3 years, 8 months agoDerekKey
3 years, 8 months ago[Removed]
3 years, 8 months agocldy
3 years, 8 months agoAyusef
3 years, 8 months agoHudda
3 years, 9 months ago