Courseiva

DOP-C02 Incident and Event Response Practice Question

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer. During a security incident, the security team needs to isolate a compromised instance for forensic analysis without affecting the application's availability. What is the MOST effective action to take?

⚠ Common exam trap

A common mix-up: candidates confuse network-level isolation (security groups or route tables) with application-level isolation (target group deregistration), failing to recognize that the ALB continues to route traffic to a registered instance regardless of its security group or subnet routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deregister the instance from the target group and stop the instance for forensic analysis.

Deregistering the instance from the target group removes it from the Application Load Balancer's routing, ensuring no new traffic is sent to it while existing connections drain (connection draining). Stopping the instance preserves its memory and disk state for forensic analysis without impacting application availability, as the remaining healthy instances continue to serve traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deregister the instance from the target group and stop the instance for forensic analysis.

    Why this is correct

    Deregistering the instance from the Target Group stops new traffic from the Application Load Balancer while leaving the instance running, which preserves volatile memory for forensic collection. Stopping the instance (not terminating it) retains the EBS volumes, allowing investigators to create snapshots or attach them to a forensic workstation for offline analysis. This approach keeps the remaining fleet operational and maintains availability while containing the compromise.

  • ✗

    Modify the security group of the instance to deny all inbound and outbound traffic.

    Why it's wrong here

    Simply altering the instance's security group to deny all inbound/outbound traffic does not reliably isolate it; security groups are stateful, so existing established connections remain active until the connection state expires. Additionally, if the instance has multiple security groups attached, you must modify every one of them to deny traffic, and an attacker with OS-level access can still perform lateral movement via other mechanisms. It also prevents legitimate forensic collection by cutting off the instance from the network, so it is not a sufficient containment measure.

  • ✗

    Terminate the compromised instance immediately to prevent further damage.

    Why it's wrong here

    Terminating the instance immediately deletes the VM and, by default, the root EBS volume when DeleteOnTermination is enabled, which destroys critical forensic evidence such as malicious files, logs, and memory dumps. It is an irreversible action that precludes any live analysis, memory capture, or further investigation of the attacker's activities and may violate compliance or legal hold requirements. Therefore, termination should be a last resort, not the first response, in a compromised instance.

  • ✗

    Change the subnet route table to route traffic away from the compromised instance.

    Why it's wrong here

    Changing the subnet route table is a subnet-wide change that affects all instances in that subnet, not just the compromised one, and can cause significant application disruption or routing issues. It does not prevent the compromised instance from communicating with other instances on the same subnet or via the local route, nor does it stop traffic that is already traversing the current rules. This action is too coarse-grained and unreliable for isolating a single resource for forensic investigation.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.