ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your team operates a fleet of Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. CloudWatch alarms suddenly show a surge in outbound SMTP traffic from one instance, and GuardDuty flags the same instance for possible mass-mailing worm activity. To contain the threat while keeping the application available, which action should you take first?
Enable Amazon GuardDuty across the account to gather additional threat intelligence before taking further action.
Deregister the suspicious instance from the load balancer target group and apply a restrictive security group that blocks all outbound connections.
Terminate the entire Auto Scaling group and redeploy the application from a clean, patched Amazon Machine Image (AMI).
Use AWS Systems Manager Patch Manager to immediately push the latest operating-system patches to every instance in the Auto Scaling group.
The primary goal during the containment phase of incident response is to stop an infection from spreading while preserving business operations. Detaching the suspected EC2 instance from the load balancer prevents new user traffic from reaching it, and tightening its security group to block all outbound traffic cuts off the worm's communication channel. The rest of the fleet continues serving customers, so availability is maintained. Immediately terminating the entire Auto Scaling group would disrupt service, applying patches does not stop the active outbreak, and simply enabling additional detection does not halt the malicious traffic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Auto Scaling group in AWS?
Open an interactive chat with Bash
How does GuardDuty detect threats on AWS resources?
Open an interactive chat with Bash
What is a security group in AWS and why is it important?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Systems and Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .