ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 342 - SCS-C01 discussion

Report
Export

Your company has a set of EC2 Instances defined in AWS. They need to ensure that all traffic packets are monitored and inspected for any security threats. How can this be achieved? Choose 2 answers from the options given below Please select:

A.
Use a host based intrusion detection system
Answers
A.
Use a host based intrusion detection system
B.
Use a third party firewall installed on a central EC2 instance
Answers
B.
Use a third party firewall installed on a central EC2 instance
C.
Use VPC Flow logs
Answers
C.
Use VPC Flow logs
D.
Use Network Access control lists logging
Answers
D.
Use Network Access control lists logging
Suggested answer: A, B

Explanation:

If you want to inspect the packets themselves, then you need to use custom based software A diagram representation of this is given in the AWS Security best practices

Option C is invalid because VPC Flow logs cannot conduct packet inspection.

For more information on AWS Security best practices, please refer to below URL:

The correct answers are: Use a host based intrusion detection system. Use a third party firewall installed on a central EC2 Submit your Feedback/Queries to our Experts

asked 16/09/2024
Robert Fox
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first