Courseiva

CCSP Cloud Security Operations Practice Question

A security operations center (SOC) uses AWS GuardDuty and wants to automatically isolate an Amazon EC2 instance that generates a high-severity finding. The isolation must block all network traffic except for forensic analysis traffic from a specific security subnet. Which combination of actions should be taken?

⚠ Common exam trap

It's easy for candidates to confuse IAM roles with network security controls; IAM roles manage API permissions, not network traffic, so they cannot isolate an instance at the network level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.

The most effective and least disruptive method to isolate an EC2 instance is to modify its security group to allow only traffic from a specific forensic subnet and remove all other rules. This blocks all other network traffic while enabling forensic analysis, and it can be automated via Lambda triggered by GuardDuty findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.

    Why this is correct

    Modifying the security group to allow only forensic subnet traffic effectively isolates the instance while permitting necessary forensic access. This is a common isolation technique that blocks all other inbound and outbound traffic, aligning with the requirement to block all network traffic except forensic analysis traffic.

  • ✗

    Detach the instance's Elastic Network Interface (ENI) and attach a new ENI with a restrictive security group.

    Why it's wrong here

    Detaching the primary ENI would disrupt the instance's network connectivity and may not be possible without stopping the instance. While attaching a new ENI could provide isolation, it does not automatically block all traffic and may leave the original ENI with its permissive rules if not removed, complicating the isolation.

  • ✗

    Move the instance to a new subnet with a network ACL that denies all traffic except from the forensic subnet.

    Why it's wrong here

    Moving an instance to a different subnet requires changing its IP address and may disrupt forensic analysis. Network ACLs are stateless and apply at the subnet level, but they do not provide the granular control of security groups. This approach is more complex and may not achieve the precise isolation required.

  • ✗

    Apply a new IAM role to the instance that denies all network access.

    Why it's wrong here

    IAM roles control AWS API permissions, not network traffic. They cannot block network access to or from an EC2 instance. Using an IAM role to restrict network traffic is ineffective because IAM does not manage network-level controls; security groups and network ACLs handle that.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.