AnswerCorrect answer: C — a stateless Deny-all NACL on the instance's sole-occupant subnet contains it immediately while it keeps running.
A company is testing incident response procedures for destination containment. The company needs to contain a critical Amazon EC2 instance as quickly as possible while keeping the EC2 instance running. The EC2 instance is the only resource in a public subnet and has active connections to other resources. Which solution will contain the EC2 instance IMMEDIATELY?
Create a new security group that has no inbound rules or outbound rules. Attach the new security group to the EC2 instance.
Configure the existing security group for the EC2 instance. Remove all existing inbound rules and outbound rules from the security group.
Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance. Correct Answer
Create a new VPC for isolation. Stop the EC2 instance. Create a new AMI from the EC2 instance. Use the new AMI to launch a new EC2 instance in the new VPC.
Community Votes
C
54%
A
46%
54% of anonymous learners picked answer C.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Security groups are stateful: removing or emptying rules lets already-established flows continue until they close. NACLs are stateless and evaluated per packet, so a Deny rule blocks new and in-flight traffic at once. For immediate containment of a running instance with live connections, a subnet NACL Deny is the right tool—and safe here because the subnet holds only this instance.
A critical EC2 instance must be contained at once while staying running, and it has active connections. A network ACL is stateless, so a Deny rule for inbound and outbound traffic takes effect immediately and breaks all packets, including established connections. Because the instance is the only resource in its public subnet, associating a Deny-all NACL with that subnet isolates it instantly without touching other resources. A security group is stateful and would keep existing tracked connections until they time out, so it is not immediate.
Attaching a new empty security group (option A) and leaving the original SG attached; an instance can have multiple SGs, so the old allow rules remain and tracked connections persist—not immediate containment. Removing rules from the existing SG (option B) is also stateful and keeps live connections. Option D stops the instance, violating 'keep running'.
Community Discussion (8 comments)
phmeeeee👍 1Selected: A
I go with A, why? - It not break another instance in same subnet, just only the instance. - Immediatly stopping the connection.
slydie👍 1Selected: C
Modifying Security Group Rule NEVER disrupts its tracked connections • Existing connections are kept until they time out • Use NACLs to interrupt/block connections immediately!!
TareDHakim👍 1Selected: C
sorry I meant C is the better option
TareDHakim👍 1Selected: D
while a new SG with no rules would immediately isolate an instance, the old security group would still provide connections, the question did not mention removing or replacing it. D seems to be the better option here
Pmktechno👍 2Selected: A
Creating a new security group with no inbound or outbound rules and attaching it to the EC2 instance will effectively isolate the instance from any network traffic, both incoming and outgoing. This method is quick and ensures that the instance remains running while being contained. It avoids the need to modify existing security groups or network ACLs, which could affect other resources. This approach provides immediate containment, allowing you to maintain the instance's state for further investigation and remediation.
IPLogic👍 2Selected: C
Given that there are no other resources in the subnet apart from the EC2 instance, the most immediate and effective way to contain the instance while keeping it running is: C. Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance. This approach will instantly isolate the EC2 instance from the network by denying all inbound and outbound traffic at the subnet level, ensuring no accidental connections can be made.
HappyG👍 2Selected: A
When you need to immediately contain an EC2 instance while keeping it running, applying a security group with no inbound or outbound rules is the fastest and most effective way to isolate the instance.
723993f👍 2Selected: C
nacl is stateless and will have immediate isolation effect while sgs will continue to let connections be until they end, we dont care about other ec2s in the subnet because there arent any
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
The requirement is immediate containment while the instance keeps running and has active connections. A NACL is stateless, so a single Deny rule on inbound and outbound traffic blocks all packets right away, severing established sessions. Associating that NACL with the subnet isolates the instance instantly; since it is the subnet's only occupant, no other workload is affected.
Why the Other Options Are Wrong
A attaches an empty SG but does not remove the instance's existing SG, so prior allow rules and tracked connections remain—containment is not immediate. B edits the existing SG, which is stateful and likewise preserves live connections until timeout. D stops the instance and moves it to a new VPC, violating the 'keep running' constraint and not being immediate. C is the only immediate, running-preserving option.
Community Comment Notes
Community was split C (50) vs A (42). The decisive C argument: NACLs are stateless and interrupt connections immediately, whereas security groups keep tracked connections until they end; since no other EC2 shares the subnet, the NACL affects only the target instance. A supporters noted a new empty SG isolates without disturbing neighbors, but it does not break existing connections. C meets the 'IMMEDIATELY' wording.