Preserve EC2 forensic evidence by isolating first, then capturing memory before stopping the instance

Respond to compromised resources and workloads. Identify security gaps through architectural reviews and cost analysis.
Answer Correct answer: C — detach from ASG and deregister from ALB first, then snapshot EBS and memory while running, and stop last to preserve volatile evidence.

A company has an application that runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The instances are in an Amazon EC2 Auto Scaling group and are attached to Amazon Elastic Block Store (Amazon EBS) volumes. A security engineer needs to preserve all forensic evidence from one of the instances. Which order of steps should the security engineer use to meet this requirement?

  1. Take an EBS volume snapshot of the instance and store the snapshot in an Amazon S3 bucket. Take a memory snapshot of the instance and store the snapshot in an S3 bucket Detach the instance from the Auto Scaling group. Deregister the instance from the ALB. Stop the instance.
  2. Take a memory snapshot of the instance and store the snapshot in an Amazon S3 bucket. Stop the instance. Take an EBS volume snapshot of the instance and store the snapshot in an S3 bucket. Detach the instance from the Auto Scaling group. Deregister the instance from the ALB.
  3. Detach the instance from the Auto Scaling group. Deregister the instance from the ALB. Take an EBS volume snapshot of the instance and store the snapshot in an Amazon S3 bucket. Take a memory snapshot of the instance and store the snapshot in an S3 bucket. Stop the instance. Correct Answer
  4. Detach the instance from the Auto Scaling group. Deregister the instance from the ALB Stop the instance. Take a memory snapshot of the instance and store the snapshot in an Amazon S3 bucket. Take an EBS volume snapshot of the instance and store the snapshot in an S3 bucket.

Community Votes

C
44%
B
34%
D
22%

44% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Forensic integrity depends on two things: (1) isolate the instance so the ASG does not terminate/replace it and the ALB stops sending traffic that changes state; (2) capture RAM (volatile) while the instance is running because stopping it discards memory. Capturing the EBS snapshot (crash-consistent) also while running preserves disk state. The correct sequence isolates, then snapshots memory and disk, then stops.

To preserve all forensic evidence from one instance in an Auto Scaling group behind an ALB, the engineer should first detach the instance from the Auto Scaling group and deregister it from the ALB so the ASG cannot terminate it and no new traffic mutates its state. While it is still running, capture the volatile memory snapshot and an EBS volume snapshot, then stop the instance. Memory is volatile and lost on stop, so it must be captured before stopping.

Stopping the instance before capturing memory (option D) destroys volatile RAM evidence. Or capturing memory first but stopping before detaching from the ASG (option B), which lets the Auto Scaling group terminate the instance and risk evidence loss. The recommended order isolates first, then captures memory before any stop.

Community Discussion (15 comments)

molerowan 👍 1 Selected: C
1. Isolate the Instance: Detach from Auto Scaling Group (ASG) and deregister from the ALB to prevent automatic termination or traffic routing to the instance. This ensures the instance remains available for forensic capture. 2.Capture EBS Snapshot: Take an EBS volume snapshot while the instance is still running. Though crash-consistent, this captures the disk state at a point in time. 3. Capture Memory Snapshot: Use tools like AWS Systems Manager or third-party utilities to capture the volatile memory (RAM) while the instance is running. Memory data is lost once the instance stops. 4. Stop the Instance: After capturing both disk and memory snapshots, stop the instance to prevent further changes.
zhen234 👍 1 Selected: A
https://docs.aws.amazon.com/security-ir/latest/userguide/collect-relevant-artifacts.html
Pat9595 👍 1 Selected: C
1️⃣ Preserve the Forensic Evidence 2️⃣ Capture the Data 3️⃣ Stop the Instance
TareDHakim 👍 1 Selected: C
Agreed, we need to preserve RAM running memory BEFORE we Stop the instance, otherwise we'd loose critical info including: Running processes Network connections Encryption keys Unwritten logs Malicious activity in memory (e.g., malware)
SCSC02Q 👍 1 Selected: C
Its C. Can not be D as stopping instance does not preserve the memory e.g. memory is lost so no memory snapshot is possible.
milesToGo 👍 1 Selected: C
Why D? Should it not be C? How would you take a memory snapshot of a stopped instance. I looked through AWS documentation and nowhere doesit it say, it is possible to take memory snapshot of stopped EC2 instance
Ucy 👍 1 Selected: D
ANSWER D Detach from the Auto Scaling group: This ensures the Auto Scaling group does not terminate or replace the instance due to health checks or scaling policies. Deregister from the ALB: Deregistering ensures the instance stops serving traffic and avoids further modifications to its state by the application. Stop the instance: Stopping the instance prevents changes to the system state and data while preserving the current disk content and memory. Take a memory snapshot: Memory snapshots (often called RAM dumps) are essential for forensic investigations to capture data like process states, encryption keys, and active network connections. Take an EBS volume snapshot: Snapshots of EBS volumes preserve disk-level data for analysis, including deleted files and filesystem metadata.
IPLogic 👍 3 Selected: B
The correct order of steps to preserve all forensic evidence from an Amazon EC2 instance is: B. Take a memory snapshot of the instance and store the snapshot in an Amazon S3 bucket. Stop the instance. Take an EBS volume snapshot of the instance and store the snapshot in an S3 bucket. Detach the instance from the Auto Scaling group. Deregister the instance from the ALB. This sequence ensures that you capture both the memory and disk state of the instance before making any changes that could alter the evidence
723993f 👍 1 Selected: C
C - correct order why not a - detach and deregister is too late, anything can happen on the system like it can go unhealthy, this causes the asg to terminate it why not b - stopping the instance when not deregistered from asg will cause the asg to terminate it, we cannot do other ops here onward why not d - memory is lost after stopping the instance
Pmktechno 👍 1 Selected: B
Option B
Pmktechno 👍 1 Selected: D
Option D
mzeynalli 👍 2 Selected: C
Option B does not detach the instance from the Auto Scaling group or deregister it from the ALB before stopping it, which can lead to unexpected instance termination or further data changes from incoming traffic. This makes it unsuitable for preserving forensic evidence effectively. Option C follows the correct sequence to ensure that the instance is properly isolated and that both memory and disk snapshots are taken in a way that preserves the integrity of forensic evidence. For these reasons, Option C is the correct approach to ensure the proper preservation of forensic evidence, while Option B may lead to potential data loss or contamination due to improper ordering of steps.
BietTuot 👍 2 Selected: A
Correct answer is A. 1. Acquire Evidence 2. Isolation 3. Stop the Instance
dhewa 👍 2 Selected: B
This order ensures that the volatile memory is captured before the instance is stopped, preserving all necessary forensic evidence.
gkaself 👍 2 Selected: D
Correct answer is D. Instance should not be stopped

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C isolates the instance from the Auto Scaling group (preventing termination/replacement on failed health checks) and from the ALB (halting inbound traffic that could alter state) before any evidence capture. It then takes the EBS volume snapshot and the memory snapshot while the instance is still running, and only stops the instance last—preserving both disk and volatile memory evidence.

Why the Other Options Are Wrong

B captures memory before stopping (good) but stops the instance before detaching it from the ASG, so the ASG may terminate the instance and risk evidence loss. D stops the instance before taking the memory snapshot, which destroys volatile RAM. A acquires snapshots but isolates only after, leaving the instance exposed to ASG termination during capture. C is the only order that isolates first and captures memory before stopping.

Community Comment Notes

Community was split (C 38, B 29, D 19). The strongest C argument: detach/deregister first so the ASG cannot terminate the instance, then capture memory before stop (memory is lost on stop). D supporters failed to see that a stopped instance cannot yield a memory snapshot. C is the forensically sound order.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide