A security team is performing an audit of a company's AWS deployment. The security team is concerned that two applications might be accessing resources that should be blocked by network ACLs and security groups. The applications are deployed across two Amazon Elastic Kubernetes Service (Amazon EKS) clusters that use the Amazon VPC Container Network Interface (CNI) plugin for Kubernetes. The clusters are in separate subnets within the same VPC and have a Cluster Autoscaler configured.
The security team needs to determine which POD IP addresses are communicating with which services throughout the VPC. The security team wants to limit the number of flow logs and wants to examine the traffic from only the two applications.
Which solution will meet these requirements with the LEAST operational overhead?
rhinozD
Highly Voted 1 year, 7 months agojohnconnor
1 year, 4 months agoNeo00
1 year, 5 months agoILOVEVODKA
Highly Voted 1 year, 9 months agowoorkim
Most Recent 2 months agoJonalb
6 months, 1 week agovikasj1in
10 months, 1 week agoSpaurito
1 month, 2 weeks agomarfee
10 months, 2 weeks agojopaca1216
1 year, 1 month agoArad
1 year, 1 month agoneotusca
1 year, 2 months agoCertified101
1 year, 4 months ago[Removed]
1 year, 5 months ago[Removed]
1 year, 5 months agoAdamWest
1 year, 7 months agoconfusedyeti69
11 months, 2 weeks agoAdamWest
1 year, 7 months agoChinmoy
1 year, 7 months agosjoe
1 year, 8 months agoKristin01
1 year, 8 months agodremm
1 year, 8 months agosudipta0007
1 year agothat1guy
1 year, 8 months agothat1guy
1 year, 8 months agolinuxek21
1 year, 8 months agostudy_aws1
1 year, 7 months ago