ISIT Security LabsIncident response training

FastCart · Production web instance fastcart-web-01

EC2 Open Security Group Investigation

Beginner15 minCloud Security / Network Security
Now: Case briefing. Read the ticket and environment first. Do not open logs until you know what you are looking for.

Ticket summary

During a routine quarterly access review, FastCart's cloud ops team is auditing security groups attached to production EC2 instances. One instance, fastcart-web-01, has a security group with a rule that looks wrong. This is not a breach report — it's a proactive review task. Review the security group's inbound rules, identify which rule is overly permissive and why, then check the instance's recent VPC Flow Logs to see whether that overly permissive rule was actually used by anyone outside FastCart, and recommend the fix.

The instance under review is fastcart-web-01 in us-east-1. It is a production web host. Your evidence locker has exactly two exports: the security group currently attached to the instance, and a short VPC Flow Log excerpt for that instance's network interface on 10 April 2026.

This is a clean, standalone review. It does not continue any other FastCart ticket, and you are not looking for an attacker identity, stolen credentials, or a persistence mechanism. Spot the misconfiguration, confirm whether it was used, and recommend how to scope the rule correctly.