🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 8 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your SOC detects abnormal outbound connections from a Linux EC2 instance in a production VPC and suspects it is part of a botnet. The team must immediately isolate the workload to stop lateral movement, but analysts still need SSH access from a dedicated incident-response subnet to collect volatile evidence. Which action is the most effective way to meet these goals while leaving other instances in the subnet unaffected?

  • Stop the instance, create an AMI, and relaunch it in an isolated VPC for analysis.

  • Change the subnet's route table to point 0.0.0.0/0 at the black-hole target to drop all external traffic.

  • Add DENY rules to the subnet's network ACL to block all outbound ports for the instance's private IP.

  • Run the Systems Manager automation document AWSSupport-QuarantineEC2Instance to replace the instance's security groups with a quarantine group that only permits SSH from the incident-response subnet.

ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot