You need to create a baseline of normal traffic flow in order to implement some security changes to your organization. What two items would be best to use? (Choose two.)
i would say C and D are better options then A and D, If you want to see a baseline of normal traffic wireshark is only going to help you per instance, if you have 100 EC2 then you need to deploy this 100 times, instead a IDS will capture all the traffic and report on all of it
not sure how cloudwatch can help with traffic pattern without VPC flow log.. I thought it should be IDS or Wireshare (not scalable solution but doable)
CloudWatch would be leveraged for monitoring and alarming once the baseline has been captured.
I also agree with @kentik in that Wireshark is instance specific, therefore if you want to capture the baseline for all traffic within your VPC, then an IDS would be the proper method.
If I'm trying to setup a baseline of normal traffic, I'm not using wireshark. lol. Wireshark is for troubleshooting/analyzing packets on a deeper level. I don't know anyone that uses Wireshark for setting up a baseline of network traffic. I've been doing this for 27 years. C/D for me.
I stand corrected. This URLs explains how to use Wireshark for establishing a network baseline.
https://wiki.wireshark.org/uploads/__moin_import__/attachments/KnownBugs/OutOfMemory/Using-Wireshark-to-Create-Network-Usage-Baselines.pdf
IDS - Intrusion Detection, not designed to setup a Network Traffic Flow baseline. Definitely not Cloud Trail, so based on elimination, has to be WireShark and Cloudwatch (Logs can capture from VPC Flow Logs and you can set baseline on metric captured)
I would also say C and D are better option. Set up an IDS and send all VPC traffic through the IDS ENI. The IDS will se all traffic into and out of the VPC enabling you to create a baseline. CW keeps historical metrics which can be used for baselining as well.
upvoted 3 times
...
This section is not available anymore. Please use the main Exam Page.ANS-C00 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Kentik
Highly Voted 3 years, 10 months agoPaagee
3 years, 10 months agoKMak
3 years, 10 months agoFireTv
Highly Voted 3 years, 5 months agoarhelp
Most Recent 1 year, 7 months agoarhelp
1 year, 7 months agoHermin
3 years, 7 months agojyrajan69
3 years, 7 months agoceros399
3 years, 8 months agoChauPhan
3 years, 9 months agostudent2020
3 years, 10 months ago