A security engineer is investigating a GuardDuty finding of type 'Backdoor:EC2/C&CActivity.B!DNS'. Which TWO actions should the engineer take as part of the initial response? (Choose two.)
Replacing the instance's security group with one that has no inbound or outbound rules immediately severs network paths used for command-and-control, data exfiltration, and lateral movement while the operating system keeps running. Security groups act as a stateful virtual firewall, so removing all allow rules drops existing connections and blocks new ones without terminating the instance. This containment preserves volatile memory and disk state for subsequent forensic collection, making it the correct first response.
Why this answer
Isolating the EC2 instance by modifying its security group to deny all traffic is a critical containment step in incident response. This immediately stops the C2 (command and control) communication detected by GuardDuty's 'Backdoor:EC2/C&CActivity.B!DNS' finding, preventing further data exfiltration or lateral movement while preserving the instance for forensic analysis.
Exam trap
The trap here is that candidates may confuse incident response containment with eradication, choosing immediate termination (Option C) instead of isolation and forensic preservation (Option B and D).