exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 4 discussion

A web company is looking to implement an intrusion detection and prevention system into their deployed VPC. This platform should have the ability to scale to thousands of instances running inside of the VPC.
How should they architect their solution to achieve these goals?

  • A. Configure an instance with monitoring software and the elastic network interface (ENI) set to promiscuous mode packet sniffing to see an traffic across the VPC.
  • B. Create a second VPC and route all traffic from the primary application VPC through the second VPC where the scalable virtualized IDS/IPS platform resides.
  • C. Configure servers running in the VPC using the host-based 'route' commands to send all traffic through the platform to a scalable virtualized IDS/IPS.
  • D. Configure each host with an agent that collects all network traffic and sends that traffic to the IDS/IPS platform for inspection.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ReggieR2
Highly Voted 3 years, 7 months ago
So i googled and found this on A nother Cloud G u r u site: B is the correct answer. The key line of the question is - "thousands of instances running in the VPC" . Option C does not confirm that the incoming traffic is passed through the IDS/IPS before reaching the host, which is one of the primary feature/requirement of any IDS/IPS. THe traffic will need to pass through the IDS so that any vulnerability could be assessed. Moreover in Option C, you can not expect to manage thousands and thousands of Servers through host based routing. Option A is invalid as promiscuous mode is not supported in AWS. Option D does not meet the IPS requirement and moreover although it can perform IDS activities but again it is not a scalable solution. SO, OPTION B is the correct ANSWER.
upvoted 29 times
JAWS1600
3 years, 6 months ago
I found the same Cloud G U R U Jayendra Patil is wrong. B is the right answer
upvoted 2 times
...
...
skywalker
Highly Voted 3 years, 7 months ago
I will go for "B" as this is how IDS/IPS are being deploy. "D" not possible as this will create additional CPU workload which should be prevent.
upvoted 7 times
nitinz
3 years, 6 months ago
D is correct answer. you can scale IDS/IPS depending on the volume.
upvoted 1 times
...
...
Chinta
Most Recent 7 months, 1 week ago
D is the correct answer
upvoted 1 times
...
amministrazione
8 months, 3 weeks ago
B. Create a second VPC and route all traffic from the primary application VPC through the second VPC where the scalable virtualized IDS/IPS platform resides.
upvoted 1 times
...
Narendragpt
9 months, 3 weeks ago
Its says within a VPC . So best option is D . configuring each host with an agent that collects and sends network traffic to a centralized IDS/IPS platform (option D) is the best approach for achieving scalable and effective intrusion detection and prevention in a VPC
upvoted 1 times
...
Bereket
10 months, 3 weeks ago
Configure each host with an agent that collects all network traffic and sends that traffic to the IDS/IPS platform for inspection.
upvoted 1 times
...
Andy85
1 year, 8 months ago
Answer: b
upvoted 1 times
...
autobahn
1 year, 9 months ago
Selected Answer: B
It has to be 'B'
upvoted 1 times
...
Tarila79
1 year, 11 months ago
Selected Answer: B
By creating a second VPC and routing all traffic from the primary application VPC through the second VPC where the scalable virtualized IDS/IPS platform resides. By separating the IDS/IPS platform into its own VPC, you can control the network traffic flow and apply security measures effectively. This architecture allows for scalability by handling the traffic from the primary application VPC through the dedicated IDS/IPS VPC, where the virtualized IDS/IPS platform can analyze and monitor the traffic.
upvoted 1 times
...
zmfly
1 year, 12 months ago
Selected Answer: B
B is correct
upvoted 1 times
...
TigerInTheCloud
2 years, 5 months ago
Selected Answer: B
A. Not scalable B. Doable, C. Traffic reaches the hosts before IDS/IPS processing, IDS may be okay but not IPS D. The same issue as C, and scalability is not mentioned. So my choice is C
upvoted 1 times
...
Snip
2 years, 6 months ago
Only B can be the right answer, IDS/IPS must analyze traffic BEFORE the traffic reach the instance
upvoted 1 times
...
skywalker
2 years, 8 months ago
B... Security Team need a clean room or network for IDS/IPS.. Seperate VPC is the answer
upvoted 2 times
...
aandc
2 years, 10 months ago
B, Gateway Load Balancer is needed https://docs.aws.amazon.com/elasticloadbalancing/latest/gateway/getting-started.html
upvoted 1 times
...
[Removed]
2 years, 10 months ago
B. There was a similar question and its answer was such as B.
upvoted 1 times
...
HellGate
3 years ago
Selected Answer: D
There's same question at official exam from AWS.
upvoted 1 times
...
bkrish
3 years, 1 month ago
D --> This architecture is better suited for HIPAA compliance customers where they make use of the Gateway Load balancer. CISCO NGFW integration with Gateway Load Balancer is a classic example for this type of scenario.
upvoted 2 times
bkrish
3 years, 1 month ago
Typo with the above option. It's B.
upvoted 2 times
orwolfstein
1 year, 8 months ago
https://aws.amazon.com/elasticloadbalancing/gateway-load-balancer/ AWS mentions this as a use case in the GLB webpage. this is definitely the correct approach
upvoted 1 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago