AnswerCorrect answer: C — a Lambda detaches and tags the EBS volumes for forensics then terminates the infected instance; moving VPCs is impossible.
A company runs workloads that are spread across hundreds of Amazon EC2 instances. During a recent security incident, an EC2 instance was compromised and ran malware code until the company manually terminated the instance. The company is now using Amazon GuardDuty to detect malware on EC2 instances. A security engineer needs to implement a solution that automates a response when GuardDuty determines that an instance is infected. The solution must mitigate the incident and must comply with the AWS Well-Architected Framework guidance for incident response. Which solution will meet these requirements?
Configure AWS Systems Manager Run Command to run when a GuardDuty scan determines that an instance is infected. Use Run Command to remove all network adapters from the operating system of the infected instance. Use Run Command to also add a tag of “Infected” to the instance.
Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to delete all elastic network interfaces that are associated with the instance. Program the Lambda function to also add a tag of “Infected” to the instance.
Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to detach all Amazon Elastic Block Store (Amazon EBS) volumes from the instance. Program the Lambda function to also add a tag of “Infected” to the EBS volumes and to terminate the instance afterward. Correct Answer
Define a separate VPC to isolate EC2 instances. Define a security group that does not allow any network traffic. Create an AWS Lambda function that runs when a GuardDuty scan determines that an instance is infected. Program the Lambda function to move the instance into the separate VPC and to assign the security group to the instance.
Community Votes
C
57%
D
43%
57% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
EC2 instances are bound to their VPC/subnet at launch and cannot be relocated, which rules out VPC-move isolation. Detaching the EBS volumes before termination preserves the compromised disk for forensics (Well-Architected IR: collect evidence), and tagging marks it for tracking; terminating the instance stops the malware's compute. Deleting ENIs (option B) disrupts the instance without clean forensic preservation.
When GuardDuty detects malware on an EC2 instance, an automated response must mitigate and follow incident-response best practices. An EC2 instance cannot be moved to another VPC or subnet, so the viable automation is a Lambda that detaches the instance's EBS volumes (preserving them as forensic evidence), tags the volumes 'Infected', and then terminates the instance—removing the threat while retaining the disk for investigation.
Trying to move the instance to a separate isolation VPC (option D)—impossible, instances cannot change VPC/subnet after launch, so this design cannot work. Or only deleting ENIs/removing adapters (options A/B), which disconnects but does not preserve forensic disk evidence as cleanly as detaching and tagging EBS.
Community Discussion (11 comments)
zhen234👍 1Selected: D
To follow AWS Well-Architected Framework incident response best practices, the infected EC2 instance must be isolated to prevent further damage.
FlyingHawk👍 2Selected: C
Based on this doc, none of the above options is good, for a compromise ec2, we first need to isolate it with the security group and network ACL and turn on the termination protection, gather all metadata, then detach its EBS volume, tag it, then terminate it. I will select C.
WhoSec👍 1Selected: D
D is the only answer that is in compliance with AWS Well-Architected Framework: Incident Response Best Practices: The framework emphasizes automating incident response and isolating affected resources. Forensics Support: By isolating the instance instead of deleting or terminating it, the company retains the ability to perform forensic analysis and determine the root cause of the incident. Least Privilege Principle: The use of a specific security group for isolation limits unnecessary exposure.
TareDHakim👍 3Selected: C
cannot be D, as you can't move an instance to a different subnet, let alone a different vpc.
youonebe👍 3Selected: D
B: This solution uses an AWS Lambda function to respond to a GuardDuty finding by deleting the elastic network interfaces (ENIs) associated with the infected instance. While this will disconnect the instance from the network, preventing further communication, deleting ENIs could have unintended consequences, such as disrupting the instance's availability or interrupting legitimate processes. C: Detaching the EBS volumes could prevent the malware from accessing persistent storage, and terminating the instance would stop the malware from running. This is a more thorough isolation and remediation approach. Adding a tag to the EBS volumes can also help with tracking and auditing. However, simply detaching EBS volumes might not prevent the malware from spreading if the instance is not immediately terminated. A more comprehensive action is required.
urbanmonk👍 2Selected: C
Not D, EC2 instances CANNOT be moved to a differrent subnet/VPC.
8acf42c👍 1Selected: D
Effectively mitigates the incident while allowing forensic investigation
Pmktechno👍 1Selected: D
This approach isolates the compromised instance, preventing it from communicating with other instances and the internet, which helps contain the incident. It also aligns with best practices for incident response by ensuring that the infected instance is quarantined effectively.
awsleffe👍 4Selected: C
For (D) you can't move an EC2 to a different VPC.
Curl8012👍 3Selected: D
D for me
jdx000👍 2Selected: C
can not be B and D
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
GuardDuty malware findings can trigger a Lambda that detaches the instance's EBS volumes, tags them 'Infected' for forensic tracking, and terminates the instance. This contains the threat (no running malware) while preserving the volumes for post-incident analysis, aligning with automated, evidence-preserving incident response. It is implementable, unlike VPC relocation.
Why the Other Options Are Wrong
A and B remove network adapters via Run Command or Lambda but do not preserve forensic disk evidence as deliberately as detaching and tagging EBS. D is invalid because an EC2 instance cannot be moved to a different VPC or subnet; the isolation design cannot be executed. C is the workable, forensically sound automation.
Community Comment Notes
Community favored C (57 votes). Commenters stressed you cannot move an EC2 to another VPC/subnet, eliminating D, and that detaching/tagging EBS then terminating preserves forensics per IR best practices. D supporters wanted isolation for forensics but the mechanism is impossible; C is the implementable answer.