exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 218 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 218
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A security engineer has noticed that VPC Flow Logs are getting a lot of REJECT traffic originating from a single Amazon EC2 instance in an Auto Scaling group.
The security engineer is concerned that this EC2 instance may be compromised.
What immediate action should the security engineer take?

  • A. Remove the instance from the Auto Scaling group. Close the security group with ingress only from a single forensic IP address to perform an analysis.
  • B. Remove the instance from the Auto Scaling group. Change the network ACL rules to allow traffic only from a single forensic IP address to perform an analysis. Add a rule to deny all other traffic.
  • C. Remove the instance from the Auto Scaling group. Enable Amazon GuardDuty in that AWS account. Install the Amazon Inspector agent on the suspicious EC2 instance to perform a scan.
  • D. Take a snapshot of the suspicious EC2 instance. Create a new EC2 instance from the snapshot in a closed security group with ingress only from a single forensic IP address to perform an analysis.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
sapien45
Highly Voted 2 years, 8 months ago
Selected Answer: A
you want to isolete the EC2 instance and not the whole subnet. So restrictions must take place at the SG level, and not the NACL level
upvoted 6 times
...
pal40sg
Most Recent 1 year, 11 months ago
Selected Answer: A
A. By removing the suspicious EC2 instance from the Auto Scaling group, you isolate it from the production environment to prevent potential further impact or compromise. Closing the security group with ingress only from a single forensic IP address allows you to restrict access to the instance for analysis purposes. This way, you can perform a detailed investigation on the isolated instance without exposing it to potential threats.
upvoted 1 times
...
G4Exams
2 years ago
Selected Answer: A
Clearly A
upvoted 1 times
...
ITGURU51
2 years ago
Isolating the security group is considered the best practice according to AWS, most importantly making changes to the NACL would impact all the computers systems on the subnet.
upvoted 1 times
...
Maya77
2 years, 2 months ago
Selected Answer: A
A. Remove the instance from the Auto Scaling group. Close the security group with ingress only from a single forensic IP address to perform an analysis is the most appropriate immediate action for the security engineer to take. Removing the instance from the Auto Scaling group prevents any new instances from being launched. Closing the security group with ingress only from a single forensic IP address allows the security engineer to perform an analysis of the instance's traffic in a controlled and secure manner. This analysis can help determine whether the instance is compromised and identify the source of the REJECT traffic.
upvoted 2 times
...
arpgaur
2 years, 3 months ago
okay, A is justified, however, the wording let me to believe that I am changing the SG for the entire group that this compromised instance (all the instances that are part of the auto-scaling group). which is not an ideal solution.
upvoted 3 times
nairj
2 years, 1 month ago
SG is instance based so it's assumed that the SG in question refers to the compromised instance.
upvoted 1 times
...
...
sahanpere
2 years, 4 months ago
A is the Answer. D is wrong cause taking only snapshot not prevent the compromising. You have to remove it from the ASG and isolate the instance first.
upvoted 3 times
...
lotfi50
2 years, 10 months ago
Selected Answer: A
A is answer
upvoted 2 times
...
roger8978
3 years, 4 months ago
First course of action is A
upvoted 4 times
...
kiev
3 years, 6 months ago
A for me as this is traffic coming from an EC2 instance and therefore SG is what is important here.
upvoted 4 times
...
Kdosec
3 years, 6 months ago
A is reasonable. Can't B because "Change the network ACL rules to allow traffic only from a single forensic IP address to perform an analysis. Add a rule to deny all other traffic.", it will block all other traffic to your Subnet / VPC.
upvoted 4 times
...
Ayusef
3 years, 6 months ago
Its ..A..(pmjcr) Security Groups handle traffic at the instance level. Dont let the wording fool you.
upvoted 1 times
...
pmjcr
3 years, 6 months ago
For me is B. Security Groups can only block incoming traffic. Question states "VPC Flow Logs are getting a lot of REJECT traffic originating from a single Amazon EC2". The fraffic is originating FROM the EC2 instance. So we need to block the outgoing traffic to avoid more exposure. NACLs are the only option that allow That. We cna block all other traffic in/out and allow inly in from the forensic IP
upvoted 2 times
f4bi4n
3 years ago
If you remove the outbound rule it can't communicate. Then only the Forensic Instance can connect to it. What worries me is that A and B would kill all other Instances because it's not mentioned that you add a new SG / the NACL would deny the hole subnet traffic. But anyway, I would go with A
upvoted 1 times
...
...
sanjaym
3 years, 6 months ago
"A" makes more sense than others.
upvoted 3 times
...
Hungdv
3 years, 6 months ago
A is answer
upvoted 3 times
...
Justu
3 years, 6 months ago
D could be also feasible answer
upvoted 3 times
skipbaylessfor3
3 years, 6 months ago
The wording seems off, how can you take a snapshot of an EC2 instance? Unless they mean EBS volume but its not mentioned
upvoted 2 times
...
Daniel76
3 years, 6 months ago
That will mean forget about containment and go straight into investigation.
upvoted 3 times
...
...
Hungdv
3 years, 6 months ago
A is answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago