exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 25 discussion

Exam question from Amazon's ANS-C00
Question #: 25
Topic #: 1
[All ANS-C00 Questions]

You have been asked to monitor traffic flows on your Amazon EC2 instance. You will be performing deep packet inspection, looking for atypical patterns.
Which tool will enable you to look at this data?

  • A. Wireshark
  • B. VPC Flow Logs
  • C. AWS CLI
  • D. CloudWatch Logs
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
References:
https://www.slideshare.net/TeriRadichel/packet-capture-on-aws

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ugreenhost
Highly Voted 3 years, 7 months ago
A is correct
upvoted 13 times
Rim007
3 years, 7 months ago
Yes A is answer
upvoted 3 times
...
certificatores
3 years, 6 months ago
it is weird to see AWS keeps promoting 3rd party tools in this exam. totally opposite logic of AWS solution architect exams
upvoted 4 times
...
...
PavanKushwah123
Most Recent 2 years, 4 months ago
Correct Answer A
upvoted 1 times
...
Balki
2 years, 4 months ago
Selected Answer: A
https://diegooo.com/wireshark-ec2-aws/
upvoted 1 times
...
ChauPhan
3 years, 6 months ago
Only A. Wireshark can "performing deep packet inspection, looking for atypical patterns".
upvoted 2 times
...
RahulMishra
3 years, 6 months ago
Wireshark from market place as Deep packet inspection is not natively available
upvoted 1 times
...
OKMAN
3 years, 6 months ago
Answer is A . DEEP PACKET INSPECTION on your EC2
upvoted 1 times
...
andyo
3 years, 6 months ago
A is CORRECT. What initially was confusing was "atypical patterns". BUT the main term is "DEEP PACKET INSPECTION". B, C, or D do not do this. The only tool in the line up that does that, even though with manual intervention is WIRESHARK.
upvoted 1 times
...
backfringe
3 years, 6 months ago
agree A is the only packet inspection tool among the options
upvoted 2 times
...
Alex_sot
3 years, 7 months ago
I think A is correct, the only option which can provide actual packet inspection
upvoted 1 times
...
Ajani
3 years, 7 months ago
i think the ans COULD possibly be D. The question is about monitoring. Wireshark is protocol analyzer (you can Monitor), meaning you need a capture tool like tcpdump or setting instance ENI to promiscuous mode..) to actually capture/sniff the packet; this doesn't scale and the AWS hypervisor will not allow an instance , y to sniff another instance x's traffic. so A is out. B, vpc flow log is definitely a capture tool, infact the cleanest ,scalable way, if we are monitoring 100's of instances(flows at vpc,subnet and eni levels). But you still need to publish VPC flow logs to cloudwatch logs "TO LOOK" at the data. https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs-cwl.html. the ambiguity of these questions are ridiculous!!! Maybe am over thinking it ?.
upvoted 2 times
tipzzz
3 years, 7 months ago
i think you'are right : https://www.youtube.com/watch?v=2s2xcwm8QrM
upvoted 1 times
...
Homosapien
3 years, 6 months ago
Cloudwatch does not allow you to analyze network packets, so that's a no
upvoted 1 times
...
...
carlopin
3 years, 7 months ago
A is the best answer, But this is a aws exam the no ask you any tools outside the scope of aws, for my in this exam the correct option is B
upvoted 1 times
...
BillyC
3 years, 7 months ago
A is correct
upvoted 1 times
...
al_zo
3 years, 7 months ago
It can't be B. VPC flow logs is not a deep packet inspection tool, it only capture metadata of data. A is correct.
upvoted 2 times
...
viduvivek
3 years, 7 months ago
Answer is B : VPC flow logs. https://aws.amazon.com/answers/networking/vpc-network-management-and-monitoring/ VPC Flow Logs capture network flow information for a VPC, subnet, or network interface in Amazon CloudWatch Logs. Flow logs can help you with a number of tasks, such as troubleshooting why specific traffic is not reaching an instance, which in turn can help you diagnose overly restrictive security group rules. You can also use flow logs as a security tool to monitor the traffic that is reaching your instance, to profile your network traffic, and to look for abnormal traffic behaviors. A common use of VPC flow logs is to watch for abnormal and unexpected denied outbound connection requests, which could be an indication of a misconfigured or compromised EC2 instance. CloudWatch Alerts can provide rudimentary network alerting on VPC Flow Logs, however AWS APN members provide third-party log management systems that provide extensive reporting, visualization, and alerting capabilities based on VPC Flow Log data.
upvoted 2 times
AdamSmith
3 years, 7 months ago
bro you have no idea what Deep Package Inspection means
upvoted 16 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago