SCS-C02 exam dumps

SCS-C02 practice question 380 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 380

Single answer

An organization has deployed an application on Amazon EC2 instances in a VPC. The security team has noticed unusual outbound traffic patterns from one of the instances, and they suspect that the instance may be compromised. As a security engineer, what is the most appropriate action to isolate the instance and investigate the issue while minimizing impact on the application?

  1. A

    Stop the instance immediately to prevent further compromise.

  2. B

    Detach the instance from the Auto Scaling group and assign it to a quarantine security group with no outbound access.

  3. C

    Terminate the instance and replace it with a new instance from a known clean AMI.

  4. D

    Enable Amazon GuardDuty and wait for additional findings before taking any action.

Show answer and explanation

Correct answer: B

Explanation

The best course of action is to isolate the instance by detaching it from the Auto Scaling group and assigning it to a quarantine security group with no outbound access. This approach ensures the instance is contained while preserving its state for forensic investigation. Immediate termination or stopping the instance would result in the loss of valuable evidence, and waiting for additional findings could worsen the situation.

  • A. Incorrect.

    Stopping the instance immediately might prevent further compromise, but it also destroys the current state of the instance, which is critical for forensic investigation.

  • B. Correct.

    Detaching the instance from the Auto Scaling group and assigning it to a quarantine security group allows you to isolate the instance while preserving its state for further investigation. This is the most appropriate action.

  • C. Incorrect.

    Terminating the instance would result in the loss of evidence required for investigation, making it difficult to determine the root cause of the issue.

  • D. Incorrect.

    While enabling Amazon GuardDuty is a good security practice, waiting for additional findings without isolating the instance could allow the compromise to spread or cause further damage.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam