SCS-C02 Infrastructure Security Practice Question
A company's security team discovers that an Amazon EC2 instance has been compromised and is sending outbound traffic to a known malicious IP address. The instance is in a VPC with a security group that allows all outbound traffic. What is the FASTEST way to stop the outbound traffic without affecting other instances?
⚠ Common exam trap
Many candidates confuse security groups with network ACLs, assuming that a NACL change is faster or more precise, when in fact security groups are instance-level and can be modified instantly without affecting other instances, making them the fastest and most targeted solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the security group attached to the instance to revoke all outbound rules.
Security groups are stateful and act as a virtual firewall at the instance level. By revoking all outbound rules in the security group attached to the compromised EC2 instance, you immediately block all outbound traffic from that specific instance without affecting any other instances in the VPC. This is the fastest and most targeted action because it requires no changes to subnet-level configurations or instance termination.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the network ACL of the subnet to deny outbound traffic to the malicious IP.
Why it's wrong here
Modifying the network ACL applies the rule to every instance in that subnet, not just the compromised one, so other workloads could lose outbound connectivity. Additionally, NACLs are stateless, meaning you must account for rule ordering and ensure return traffic is handled, which adds complexity and risk. This broad blast radius makes it a poor choice for targeted isolation.
- ✗
Change the route table of the subnet to route traffic to a blackhole.
Why it's wrong here
Changing the route table to a blackhole redirects traffic destined for the malicious IP to a null target, but route tables are associated at the subnet level, so all instances sharing that route table are impacted. If the compromised instance uses a different route table or has multiple ENIs, the change might not even affect it, and you could inadvertently disrupt other applications. This is a network-layer wrench rather than a precise security control.
- ✗
Terminate the compromised EC2 instance immediately.
Why it's wrong here
Terminating the instance immediately is irreversible and destroys volatile memory and disk state, which may be needed for forensic investigation or evidence preservation. It also does not address the root cause if the instance is part of an Auto Scaling group, as a replacement could be launched with the same vulnerability. Controlled isolation is preferable to allow data capture before destroying the resource.
- ✓
Modify the security group attached to the instance to revoke all outbound rules.
Why this is correct
Security groups are stateful, instance-level firewalls, so modifying the security group attached to the instance to revoke all outbound rules will immediately block the compromised instance's egress traffic without affecting other instances in the subnet. Changes apply instantly to the ENI, and because security groups are scoped to the instance, this provides precise, surgical isolation. This is the fastest way to stop malicious outbound communication while preserving the instance for investigation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.