QuestionQ47

Incident Response

A company's security engineer is developing an isolation procedure for Amazon EC2 instances as part of an incident-response plan. The security engineer must isolate a target instance to block all traffic to and from it, except traffic from the company's forensics team. Each company EC2 instance has its own dedicated security group. The EC2 instances are deployed in VPC subnets, and a subnet can contain multiple instances.

The security engineer is testing the EC2 isolation procedure and opens an SSH session to the target instance. The procedure begins simulating an attacker's access to the target instance. The security engineer removes the current security-group rules and adds rules that allow the forensics team to access the target instance on port 22.

After making these changes, the security engineer finds that the SSH connection is still active and usable. When the security engineer runs a ping command against the target instance's public IP address, the ping is blocked.

What should the security engineer do to isolate the target instance?

Explanation

Amazon EC2 security groups track established connections, so modifying or removing a rule does not immediately stop a tracked SSH session. When unrestricted inbound and outbound rules are temporarily present, the flow is untracked; removing those rules immediately interrupts that SSH session. This operates on the target instance's dedicated security group and leaves the separate port 22 access rule for the forensics team intact. A subnet network ACL would also affect every instance in that subnet.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!