You have been asked to monitor traffic flows on your Amazon EC2 instance. You will be performing deep packet inspection, looking for atypical patterns. Which tool will enable you to look at this data?
A is CORRECT. What initially was confusing was "atypical patterns". BUT the main term is "DEEP PACKET INSPECTION". B, C, or D do not do this.
The only tool in the line up that does that, even though with manual intervention is WIRESHARK.
i think the ans COULD possibly be D. The question is about monitoring. Wireshark is protocol analyzer (you can Monitor), meaning you need a capture tool like tcpdump or setting instance ENI to promiscuous mode..) to actually capture/sniff the packet; this doesn't scale and the AWS hypervisor will not allow an instance , y to sniff another instance x's traffic. so A is out.
B, vpc flow log is definitely a capture tool, infact the cleanest ,scalable way, if we are monitoring 100's of instances(flows at vpc,subnet and eni levels).
But you still need to publish VPC flow logs to cloudwatch logs "TO LOOK" at the data.
https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-cwl.html.
the ambiguity of these questions are ridiculous!!! Maybe am over thinking it ?.
Answer is B : VPC flow logs.
https://aws.amazon.com/answers/networking/vpc-network-management-and-monitoring/
VPC Flow Logs capture network flow information for a VPC, subnet, or network interface in Amazon CloudWatch Logs. Flow logs can help you with a number of tasks, such as troubleshooting why specific traffic is not reaching an instance, which in turn can help you diagnose overly restrictive security group rules. You can also use flow logs as a security tool to monitor the traffic that is reaching your instance, to profile your network traffic, and to look for abnormal traffic behaviors. A common use of VPC flow logs is to watch for abnormal and unexpected denied outbound connection requests, which could be an indication of a misconfigured or compromised EC2 instance. CloudWatch Alerts can provide rudimentary network alerting on VPC Flow Logs, however AWS APN members provide third-party log management systems that provide extensive reporting, visualization, and alerting capabilities based on VPC Flow Log data.
bro you have no idea what Deep Package Inspection means
upvoted 16 times
...
...
This section is not available anymore. Please use the main Exam Page.ANS-C00 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ugreenhost
Highly Voted 3 years, 7 months agoRim007
3 years, 7 months agocertificatores
3 years, 6 months agoPavanKushwah123
Most Recent 2 years, 4 months agoBalki
2 years, 4 months agoChauPhan
3 years, 6 months agoRahulMishra
3 years, 6 months agoOKMAN
3 years, 6 months agoandyo
3 years, 6 months agobackfringe
3 years, 6 months agoAlex_sot
3 years, 7 months agoAjani
3 years, 7 months agotipzzz
3 years, 7 months agoHomosapien
3 years, 6 months agocarlopin
3 years, 7 months agoBillyC
3 years, 7 months agoal_zo
3 years, 7 months agoviduvivek
3 years, 7 months agoAdamSmith
3 years, 7 months ago