ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 337 - SCS-C01 discussion

Report
Export

One of the EC2 Instances in your company has been compromised. What steps would you take to ensure that you could apply digital forensics on the Instance. Select 2 answers from the options given below Please select:

A.
Remove the role applied to the Ec2 Instance
Answers
A.
Remove the role applied to the Ec2 Instance
B.
Create a separate forensic instance
Answers
B.
Create a separate forensic instance
C.
Ensure that the security groups only allow communication to this forensic instance
Answers
C.
Ensure that the security groups only allow communication to this forensic instance
D.
Terminate the instance
Answers
D.
Terminate the instance
Suggested answer: B, C

Explanation:

Option A is invalid because removing the role will not help completely in such a situation Option D is invalid because terminating the instance means that you cannot conduct forensic analysis on the instance One way to isolate an affected EC2 instance for investigation is to place it in a Security Group that only the forensic investigators can access. Close all ports except to receive inbound SSH or RDP traffic from one single IP address from which the investigators can safely examine the instance.

For more information on security scenarios for your EC2 Instance, please refer to below URL:

https://d1.awsstatic.com/Marketplace/scenarios/security/SEC 11 TSB Final.pd1The correct answers are: Create a separate forensic instance. Ensure that the security groups onlyallow communication to this forensic instanceSubmit your Feedback/Queries to our Experts

asked 16/09/2024
Miguel Triebel
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first