exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 916 discussion

Exam question from Amazon's AWS-SysOps
Question #: 916
Topic #: 1
[All AWS-SysOps Questions]

A company has a web application that is deployed in a VPC. Inbound traffic to this web application comes in through an internet gateway and arrives at a Network
Load Balancer (NLB). From there, the traffic travels to multiple Amazon EC2 instances in two private subnets. The company wants to perform deep packet inspection on the inbound traffic to identify potential hacking attempts.
Which solution meets these requirements?

  • A. Configure AWS Shield for the VPC.
  • B. Use AWS Network Firewall on the VPC. Configure Network Firewall to perform deep packet inspection.
  • C. Use AWS Network Firewall on the subnets. Configure Network Firewall to perform deep packet inspection.
  • D. Set up Traffic Mirroring on an inbound port of the NLB.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
doofenshmirtz
6 months, 1 week ago
its B Network Firewall can be configured to be stateful or stateless. However, Network Firewall works on the VPC level and not lower.
upvoted 1 times
...
albert_kuo
9 months ago
Selected Answer: B
By using Network Firewall in the VPC, you can have centralized control over the traffic inspection for multiple EC2 instances in the private subnets.
upvoted 1 times
...
gulu73
1 year, 2 months ago
Selected Answer: B
Answer is B
upvoted 1 times
...
task_7
1 year, 2 months ago
Ans C. Network firewall will be configured for the relevant subnets where EC2 instance are running.
upvoted 1 times
...
Cyril_the_Squirl
2 years, 5 months ago
D is possile depending on the technology you use...typically from AWS Marketplace....this is clealy out of scope here and therefore D is Wrong. | B is Correct, you need only 1 perimeter firewall and DPI is a feature of the firewall, it inspects not just the packet headers at L3-4, it inspects the full payload. In fact many NGFW have sandbox capability where they can detonate the encapsulated payload data and test if it's malicious or not...
upvoted 1 times
...
sapien45
2 years, 5 months ago
AWS Network Firewall is a stateful, managed, network firewall and intrusion detection and prevention service for your virtual private cloud (VPC) that you created in Amazon Virtual Private Cloud (Amazon VPC).With Deep packet inspection works on the payload data within your packets,
upvoted 1 times
...
Malicaide
2 years, 6 months ago
B is 100% correct. AWS Network Firewall supports deep packet inspection. AWS Network Firewall is configured on the VPC not subnet...
upvoted 3 times
...
Huy
2 years, 6 months ago
Correct answer is D. Network firewall is not to deep package inspection.
upvoted 2 times
...
cloudstudent1234
2 years, 6 months ago
Answer is B https://aws.amazon.com/blogs/networking-and-content-delivery/deployment-models-for-aws-network-firewall/
upvoted 4 times
...
USR
2 years, 6 months ago
Correct answer is B
upvoted 3 times
...
wahlbergusa
2 years, 6 months ago
I am more inclined to "B". Question mentions "Deep Packet Inspection". => https://docs.aws.amazon.com/network-firewall/latest/developerguide/firewall-policy-processing.html
upvoted 2 times
...
qurren
2 years, 6 months ago
https://docs.aws.amazon.com/vpc/latest/mirroring/tm-example-inbound-tcp.html
upvoted 3 times
...
qurren
2 years, 7 months ago
Answer is D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago