Which response will immediately mitigate the attack and help investigate the root cause?

1 Comment

  1. Pamela
    Author

    As I understand it, the answer is:
    Update the outbound network ACL for the subnet in us-east-1b to explicitly deny all connections as the first rule. Replace the security group with a new security group that allows connections only from a diagnostics security group. Update the outbound network ACL for the us-east-1b subnet to remove the deny all rule. Launch a new EC2 instance that has diagnostic tools. Assign the new security group to the new EC2 instance. Use the new EC2 instance to investigate the suspicious instance.

Leave a Reply to Pamela Cancel reply

Your email address will not be published. Required fields are marked *

15 − 8 =