Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Advanced Networking - Specialty ANS-C01 All Questions

View all questions & answers for the AWS Certified Advanced Networking - Specialty ANS-C01 exam

Exam AWS Certified Advanced Networking - Specialty ANS-C01 topic 1 question 143 discussion

A company has an application that runs on a fleet of Amazon EC2 instances. A new company regulation mandates that all network traffic to and from the EC2 instances must be sent to a centralized third-party EC2 appliance for content inspection.

Which solution will meet these requirements?

  • A. Configure VPC flow logs on each EC2 network interface. Publish the flow logs to an Amazon S3 bucket. Create a third-party EC2 appliance to acquire flow logs from the S3 bucket. Log in to the appliance to monitor network content.
  • B. Create a third-party EC2 appliance in an Auto Scaling group fronted by a Network Load Balancer (NLB). Configure a mirror session. Specify the NLB as the mirror target. Specify a mirror filter to capture inbound and outbound traffic. For the source of the mirror session, specify the EC2 elastic network interfaces for all the instances that host the application.
  • C. Configure a mirror session. Specify an Amazon Kinesis Data Firehose delivery stream as the mirror target. Specify a mirror filter to capture inbound and outbound traffic. For the source of the mirror session, specify the EC2 elastic network interfaces for all the instances that host the application. Create a third-party EC2 appliance. Send all traffic to the appliance through the Kinesis Data Firehose delivery stream for content inspection.
  • D. Configure VPC flow logs on each EC2 network interface. Send the logs to Amazon CloudWatch. Create a third-party EC2 appliance. Configure a CloudWatch filter to send the flow logs to Amazon Kinesis Data Firehose to load the logs into the appliance.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Wiss7
Highly Voted 1 year, 4 months ago
Selected Answer: B
You can use the following resources as traffic mirror targets: Network interfaces of type interface Network Load Balancers Gateway Load Balancer endpoints https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-targets.html
upvoted 7 times
...
Spaurito
Most Recent 1 week, 3 days ago
B - Traffic must be sent to and from the 3rd party for inspection. Doesn't define before connecting to endpoints but assuming it does, B would be the solution. C is just capturing the data. Then what.
upvoted 1 times
...
Arad
1 year ago
Selected Answer: B
B is the right answer.
upvoted 2 times
...
Cheam
1 year, 1 month ago
Selected Answer: B
Similar question to #21. All the best.
upvoted 3 times
...
[Removed]
1 year, 3 months ago
Selected Answer: B
B because the question is also using a third party tool.
upvoted 3 times
...
wartywarthog
1 year, 4 months ago
Answer is B. Kinesis Firehose is not a mirror target https://docs.aws.amazon.com/vpc/latest/mirroring/traffic-mirroring-target.html
upvoted 3 times
...
AJ7428
1 year, 4 months ago
Selected Answer: B
NLB configured as mirror target, can't use Amazon Kinesis Data Firehose delivery stream.
upvoted 3 times
...
Balasmaniam
1 year, 4 months ago
Route 53 – Resolver Query Logging • Logs all DNS queries made by resources within a VPC • Private Hosted Zones • Resolver Inbound & Outbound Endpoints • Resolver DNS Firewall • Can send logs to CloudWatch Logs, S3 bucket, or Kinesis Data Firehose • Configurations can be shared with other AWS Accounts using AWS Resource Access Manager (AWS RAM) Resolver Query Logging VPC Route 53 Resolver EC2 Instance example.com? example.com? S3
upvoted 1 times
...
Balasmaniam
1 year, 4 months ago
SORRY C IS BEST ANS
upvoted 1 times
...
Balasmaniam
1 year, 5 months ago
B ans 100 %
upvoted 3 times
...
takecoffe
1 year, 5 months ago
Selected Answer: B
Option C is incorrect because configuring a mirror session to an Amazon Kinesis Data Firehose delivery stream does not involve the use of a third-party EC2 appliance for content inspection.
upvoted 3 times
...
Pratap
1 year, 5 months ago
Selected Answer: C
The best solution for meeting the requirements is to configure a mirror session and specify an Amazon Kinesis Data Firehose delivery stream as the mirror target. This will allow all network traffic to be sent to the third-party appliance for content inspection without adding any latency to the network traffic.
upvoted 2 times
...
Pratap
1 year, 5 months ago
C he best solution for meeting the requirements is to configure a mirror session and specify an Amazon Kinesis Data Firehose delivery stream as the mirror target. This will allow all network traffic to be sent to the third-party appliance for content inspection without adding any latency to the network traffic.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...