Courseiva

How to Isolate a Compromised EC2 Instance and Preserve Forensic Data

A company wants to automatically isolate an EC2 instance that is suspected to be compromised. What is the MOST effective AWS-native approach?

⚠ Common exam trap

It's easy for candidates to choose termination (Option A) thinking it is the fastest way to stop the threat, but the exam emphasizes preserving forensic evidence and using automated, reversible isolation mechanisms like security group modification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Amazon GuardDuty to detect the compromise and automatically modify the instance's security group to deny all traffic

Amazon GuardDuty can detect suspicious activity on an EC2 instance (e.g., cryptocurrency mining, unusual outbound traffic) and, when integrated with Amazon EventBridge and AWS Lambda, automatically modify the instance's security group to deny all traffic. This approach isolates the instance without terminating it, preserving forensic evidence and allowing further investigation. It is the most effective AWS-native approach because it combines threat detection with automated, least-privilege response actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terminate the instance immediately

    Why it's wrong here

    Immediately terminating the instance is an irreversible action that destroys volatile memory and disk data needed for forensic analysis, and it forfeits the ability to determine the compromise's scope and root cause. It also does not contain the threat in a way that preserves evidence; any automated scaling activity could launch a new instance from the same vulnerable AMI, recreating the exposure. Proper isolation should cut network access while keeping the instance intact.

  • ✓

    Use Amazon GuardDuty to detect the compromise and automatically modify the instance's security group to deny all traffic

    Why this is correct

    Amazon GuardDuty consumes VPC DNS logs, flow logs, and other telemetry to identify suspicious behavior such as outbound traffic to known command-and-control IPs. A high-severity finding can be sent to Amazon EventBridge, which invokes an AWS Lambda function that replaces the instance's security group with a quarantine security group containing a deny-all inbound and outbound rule, instantly severing network connectivity. This agentless containment preserves the running instance and its memory for investigation and is the recommended automated isolation pattern.

  • ✗

    Use AWS Config to change the instance's IAM role

    Why it's wrong here

    AWS Config can detect configuration drift and trigger remediation, but changing the instance's IAM role only alters the permissions available to new credential requests via the instance metadata service. It does not modify security group rules, network ACLs, or routing, so the instance can remain fully reachable on the network; in fact, a process already running with assumed role credentials can continue to use them until expiry. Therefore this action does nothing to isolate a compromised instance at the network layer.

  • ✗

    Use AWS Systems Manager to run a script that stops the instance

    Why it's wrong here

    AWS Systems Manager Run Command relies on the SSM Agent being installed, healthy, and able to communicate with the Systems Manager service. A compromised instance may have the agent stopped, tampered with, or its outbound registration traffic blocked, so the script may never execute, leaving the instance exposed, and the termination could also fail if the agent is unavailable. Additionally, stopping an instance is a guest/control-plane action rather than a network path change, and it does not preserve memory for forensic capture in the way a security-group-level block does.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.