ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 577 - SAP-C01 discussion

Report
Export

You are designing an intrusion detection prevention (IDS/IPS) solution for a customer web application in a single VPC. You are considering the options for implementing IOS IPS protection for traffic coming from the Internet. Which of the following options would you consider? (Choose two.)

A.
Implement IDS/IPS agents on each Instance running in VPC
Answers
A.
Implement IDS/IPS agents on each Instance running in VPC
B.
Configure an instance in each subnet to switch its network interface card to promiscuous mode and analyze network traffic.
Answers
B.
Configure an instance in each subnet to switch its network interface card to promiscuous mode and analyze network traffic.
C.
Implement Elastic Load Balancing with SSL listeners in front of the web applications
Answers
C.
Implement Elastic Load Balancing with SSL listeners in front of the web applications
D.
Implement a reverse proxy layer in front of web servers and configure IDS/IPS agents on each reverse proxy server.
Answers
D.
Implement a reverse proxy layer in front of web servers and configure IDS/IPS agents on each reverse proxy server.
Suggested answer: A, D

Explanation:

EC2 does not allow promiscuous mode, and you cannot put something in between the ELB and the web server (like a listener or IDP)

asked 16/09/2024
Silfredo Jimenez Munoz
35 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first