CCSP Cloud Security Operations Practice Question
A security operations center (SOC) uses AWS GuardDuty and wants to automatically isolate an Amazon EC2 instance that generates a high-severity finding. The isolation must block all network traffic except for forensic analysis traffic from a specific security subnet. Which combination of actions should be taken?
⚠ Common exam trap
It's easy for candidates to confuse IAM roles with network security controls; IAM roles manage API permissions, not network traffic, so they cannot isolate an instance at the network level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.
The most effective and least disruptive method to isolate an EC2 instance is to modify its security group to allow only traffic from a specific forensic subnet and remove all other rules. This blocks all other network traffic while enabling forensic analysis, and it can be automated via Lambda triggered by GuardDuty findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.
Why this is correct
Modifying the security group to allow only forensic subnet traffic effectively isolates the instance while permitting necessary forensic access. This is a common isolation technique that blocks all other inbound and outbound traffic, aligning with the requirement to block all network traffic except forensic analysis traffic.
- ✗
Detach the instance's Elastic Network Interface (ENI) and attach a new ENI with a restrictive security group.
Why it's wrong here
Detaching the primary ENI would disrupt the instance's network connectivity and may not be possible without stopping the instance. While attaching a new ENI could provide isolation, it does not automatically block all traffic and may leave the original ENI with its permissive rules if not removed, complicating the isolation.
- ✗
Move the instance to a new subnet with a network ACL that denies all traffic except from the forensic subnet.
Why it's wrong here
Moving an instance to a different subnet requires changing its IP address and may disrupt forensic analysis. Network ACLs are stateless and apply at the subnet level, but they do not provide the granular control of security groups. This approach is more complex and may not achieve the precise isolation required.
- ✗
Apply a new IAM role to the instance that denies all network access.
Why it's wrong here
IAM roles control AWS API permissions, not network traffic. They cannot block network access to or from an EC2 instance. Using an IAM role to restrict network traffic is ineffective because IAM does not manage network-level controls; security groups and network ACLs handle that.
Visual reference
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.