Examtopics

AWS Certified Security - Specialty
  • Topic 1 Question 246

    A company is testing incident response procedures for destination containment. The company needs to contain a critical Amazon EC2 instance as quickly as possible while keeping the EC2 instance running. The EC2 instance is the only resource in a public subnet and has active connections to other resources.

    Which solution will contain the EC2 instance IMMEDIATELY?

    • Create a new security group that has no inbound rules or outbound rules. Attach the new security group to the EC2 instance.

    • Configure the existing security group for the EC2 instance. Remove all existing inbound rules and outbound rules from the security group.

    • Create a new network ACL that has a single Deny rule for inbound traffic and outbound traffic. Associate the new network ACL with the subnet that contains the EC2 instance.

    • Create a new VPC for isolation. Stop the EC2 instance. Create a new AMI from the EC2 instance. Use the new AMI to launch a new EC2 instance in the new VPC.


    シャッフルモード