A company uses AWS to run a long-running data-analysis process on data stored in Amazon S3 buckets. The process runs on a fleet of Amazon EC2 instances in an Auto Scaling group. The EC2 instances are deployed in a private VPC subnet without internet access. The EC2 instances and the S3 buckets are in the same AWS account.
The EC2 instances access the S3 buckets through an S3 gateway endpoint with the default access policy. Each EC2 instance has an associated instance profile role whose policy explicitly permits s3:GetObject and s3:PutObject only for the required S3 buckets.
The company discovers that one or more EC2 instances have been compromised and are exfiltrating data to an S3 bucket outside the company’s AWS Organizations organization. A security engineer must implement a solution that stops this data exfiltration while keeping the EC2 processing job functional.
Which solution meets these requirements?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion