Deny all outbound at the NACL, isolate with a diagnostics security group, and investigate from a new instance

Answer Correct answer: B — deny all outbound at the NACL, isolate with a diagnostics security group, and investigate from a separate EC2 instance.

A security engineer receives a notice about suspicious activity from a Linux-based Amazon EC2 instance that uses Amazon Elastic Block Store (Amazon EBS)-based storage. The instance is making connections to known malicious addresses. The instance is in a development account within a VPC that is in the us-east-1 Region. The VPC contains an internet gateway and has a subnet in us-east-1a and us-east-1b. Each subnet is associate with a route table that uses the internet gateway as a default route. Each subnet also uses the default network ACL. The suspicious EC2 instance runs within the us-east-1b subnet. During an initial investigation, a security engineer discovers that the suspicious instance is the only instance that runs in the subnet. Which response will immediately mitigate the attack and help investigate the root cause?

  1. Log in to the suspicious instance and use the netstat command to identify remote connections. Use the IP addresses from these remote connections to create deny rules in the security group of the instance. Install diagnostic tools on the instance for investigation. Update the outbound network ACL for the subnet in us-east-1b to explicitly deny all connections as the first rule during the investigation of the instance.
  2. Update the outbound network ACL for the subnet in us-east-1 b to explicitly deny all connections as the first rule. Replace the security group with a new security group that allows connections only from a diagnostics security group. Update the outbound network ACL for the us-east-1 b subnet to remove the deny all rule. Launch a new EC2 instance that has diagnostic tools. Assign the new security group to the new EC2 instance. Use the new EC2 instance to investigate the suspicious instance. Correct Answer
  3. Ensure that the Amazon Elastic Block Store (Amazon EBS) volumes that are attached to the suspicious EC2 instance will not delete upon termination. Terminate the instance. Launch a new EC2 instance in us-east-1a that has diagnostic tools. Mount the EBS volumes from the terminated instance for investigation.
  4. Create an AWS WAF web ACL that denies traffic to and from the suspicious instance. Attach the AWS WAF web ACL to the instance to mitigate the attack. Log in to the instance and install diagnostic tools to investigate the instance.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A NACL is stateless and an explicit deny-all outbound as the first rule immediately severs the instance's network connections (both directions, since return traffic is also blocked). Isolating via a diagnostics-only SG and investigating from a separate instance avoids contaminating evidence by logging into the compromised host. Logging in and installing tools on the instance (A/D) risks tampering/destruction of evidence; WAF (D) does not attach to EC2 instances. B is the correct response.

A suspicious EC2 is connecting to malicious addresses. To immediately mitigate and preserve evidence, update the subnet NACL's outbound rules to explicitly deny all as the first rule (stateless, so it cuts both directions), replace the instance's security group with one allowing only a diagnostics SG, then launch a separate diagnostic instance to examine the suspicious one—without logging in and potentially tampering. This contains the threat and supports root-cause analysis.

Logging into the instance to run netstat/install tools (A/D)—this may alter or destroy forensic evidence and does not immediately contain the threat. Attaching a WAF web ACL to an EC2 instance (D)—WAF associates with CloudFront/ALB/API Gateway, not EC2 instances. B's NACL deny-all + separate diagnostic instance is the right containment-and-investigate approach.

Community Discussion (4 comments)

Zek 👍 6
Agree with B https://www.examtopics.com/discussions/amazon/view/110913-exam-aws-certified-security-specialty-topic-1-question-490/
NimiBes 👍 1 Selected: B
B for me
navid1365 👍 2 Selected: B
B is correct
Certified101 👍 3 Selected: B
B is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A NACL is stateless, so an explicit deny-all outbound rule as the first entry immediately blocks the suspicious instance's traffic in both directions, containing the attack at once. Replacing its security group with a diagnostics-only group and examining it from a separate, freshly launched instance preserves forensic integrity—you never log into and potentially alter the compromised host.

Why the Other Options Are Wrong

A and D have the engineer log into the instance and install tools, which can tamper with or destroy evidence and does not instantaneously contain the threat. D also wrongly attaches a WAF web ACL to an EC2 instance—WAF attaches to CloudFront, ALB, or API Gateway, not EC2. B is the correct containment-and-investigate response.

Community Comment Notes

Community voted B (100). Commenters favored the NACL deny-all outbound plus a separate diagnostics instance to avoid touching the suspicious host. B was confirmed as immediate mitigation + root-cause investigation.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide