A company's security engineer is developing an isolation procedure for Amazon EC2 instances as part of an incident-response plan. The security engineer must isolate a target instance to block all traffic to and from it, except traffic from the company's forensics team. Each company EC2 instance has its own dedicated security group. The EC2 instances are deployed in VPC subnets, and a subnet can contain multiple instances.
The security engineer is testing the EC2 isolation procedure and opens an SSH session to the target instance. The procedure begins simulating an attacker's access to the target instance. The security engineer removes the current security-group rules and adds rules that allow the forensics team to access the target instance on port 22.
After making these changes, the security engineer finds that the SSH connection is still active and usable. When the security engineer runs a ping command against the target instance's public IP address, the ping is blocked.
What should the security engineer do to isolate the target instance?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion