Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer receives an alert that an EC2 instance has been compromised. The instance is part of an Auto Scaling group. What is the first step the engineer should take to isolate the instance?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detach the instance from the Auto Scaling group and remove it from the load balancer

The first step to isolate a compromised EC2 instance in an Auto Scaling group is to detach it from the Auto Scaling group and remove it from the load balancer. This stops all incoming traffic to the instance, preventing further damage or data exfiltration while preserving the instance for forensic analysis. Option A (snapshot) is useful for preserving evidence but does not isolate the instance. Option C (AMI) similarly does not provide immediate isolation. Option D (terminate) may destroy evidence and should only be done after investigation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a snapshot of the instance's root volume

    Why it's wrong here

    Creating a snapshot of the instance's root volume does not isolate the instance from incoming traffic or from the Auto Scaling group. The instance remains fully operational and continues to serve requests, so an ongoing security incident or resource exhaustion is not mitigated. Snapshots only provide a point-in-time copy for backup or offline forensic analysis later, and the act of snapshotting does not stop processes, network connections, or lifecycle actions.

  • ✓

    Detach the instance from the Auto Scaling group and remove it from the load balancer

    Why this is correct

    Detaching the instance from the Auto Scaling group and removing it from the load balancer is the correct first step because it immediately stops new traffic from reaching the instance while also preventing the ASG from automatically replacing or terminating it. This preserves the running state for forensic collection, including memory and volatile data, and allows you to investigate safely without the instance being scaled away or continuing to affect production traffic. The instance stays alive but is decoupled from both the horizontal scaling and the request path.

  • ✗

    Create an AMI of the instance for analysis

    Why it's wrong here

    Creating an AMI of the instance for analysis is not an immediate isolation measure. AMI creation takes time and does not prevent the instance from receiving traffic or being managed by the Auto Scaling group, so the instance could be modified or terminated during the capture process. Additionally, an AMI only captures the root volume and some attached volumes at a certain point, but it does not preserve memory, network connections, or other ephemeral evidence, and it does not stop the instance from continuing its malicious or affected behavior.

  • ✗

    Terminate the instance immediately

    Why it's wrong here

    Terminating the instance immediately destroys critical forensic evidence, including the root volume, instance store volumes, and any in-memory data that might be needed to determine the root cause of the alert. It also causes the Auto Scaling group to launch a replacement instance, which can spread the issue or lead to data loss. In incident response, termination is a last resort after evidence collection, not a first step, because without the instance you lose visibility into what actually happened.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.