SOA-C02 Security and Compliance Practice Question
An administrator notices that an EC2 instance has been compromised. The instance is part of an Auto Scaling group. What should the administrator do FIRST to contain the incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detach the instance from the Auto Scaling group and apply a security group that denies all traffic.
The correct first step is to detach the instance from the Auto Scaling group and apply a security group that denies all traffic. This isolates the compromised instance, preventing further damage while preserving evidence for forensic analysis. Option A is incorrect because changing the launch configuration does not affect running instances. Option B is incorrect because immediate termination may destroy evidence. Option D is incorrect because deleting the Auto Scaling group is an extreme measure and not the immediate containment step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the Auto Scaling group's launch configuration to use a different AMI.
Why it's wrong here
Updating the Auto Scaling group's launch configuration to a different AMI affects only future launches, not the already-running compromised instance. The existing instance continues running with its original operating system, software, and configurations, so the threat remains active. This action does nothing to isolate or contain the compromised workload.
- ✗
Terminate the instance immediately.
Why it's wrong here
Terminating the instance immediately is dangerous from an incident-response perspective because it destroys volatile memory, process state, and often the EBS root volume (if delete-on-termination is enabled), erasing forensic evidence vital for identifying the attack vector and persistence mechanisms. In an Auto Scaling environment, termination would also trigger an automatic replacement instance, but you lose the ability to examine the compromised system before it disappears.
- ✓
Detach the instance from the Auto Scaling group and apply a security group that denies all traffic.
Why this is correct
Detaching the instance from the Auto Scaling group prevents the ASG from automatically replacing or terminating it due to health checks, while applying a security group that denies all traffic cuts off network communications to and from the instance. This stops command-and-control channels, data exfiltration, and lateral movement, and preserves the instance's disk and memory for forensics. This is the correct first step in EC2 incident response.
- ✗
Delete the Auto Scaling group.
Why it's wrong here
Deleting the Auto Scaling group terminates all instances managed by the group, not just the compromised one, causing a service outage and destroying forensic evidence from both the compromised and healthy instances. It is an overreactive, irreversible action that also removes scaling policies, alarms, and lifecycle hooks, and it does not enable targeted containment or investigation. You should isolate the single affected instance instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.