Question 1 · choose 2
GuardDuty reports that an EC2 instance is communicating with a known command-and-control server. The instance must later be analyzed by the forensics team, including what was running in memory. Which actions preserve the evidence the team needs? (Choose TWO.)
- AStop the instance so that its volumes are consistent, then create an AMI
- BAcquire the instance memory with forensic tooling and store it in S3
- CTerminate the instance and launch a clean replacement from the latest AMI
- DSnapshot the attached EBS volumes and share them with the forensics account
- ETurn on VPC flow logs for the instance's subnet and keep them in S3
Show the answer and why
AStop the instance so that its volumes are consistent, then create an AMI
Incorrect
Stopping the instance discards the contents of memory, which the forensics team needs.
BAcquire the instance memory with forensic tooling and store it in S3
Correct
Memory holds running processes and connections that disk snapshots do not contain, so it is acquired from the running instance first.
CTerminate the instance and launch a clean replacement from the latest AMI
Incorrect
Termination deletes volumes set to delete on termination and loses memory, destroying evidence.
DSnapshot the attached EBS volumes and share them with the forensics account
Correct
Snapshots preserve the disks and can be restored to new volumes for analysis in a separate forensics account.
ETurn on VPC flow logs for the instance's subnet and keep them in S3
Incorrect
Flow logs record future network metadata only; they do not preserve the memory or disk state of the instance.
Capture what disappears first: memory from the running instance, then the disks as snapshots. Isolation with a restrictive security group follows memory acquisition in AWS's forensics orchestration.
AWS documentation