CompTIA Cloud+ (CV0-004)SecurityHard

A financial institution is deploying a critical database in a public cloud. Due to stringent regulatory requirements (e.g., PCI DSS), all network traffic to and from this database must be inspected for malicious content and potential data exfiltration. The institution requires deep packet inspection and intrusion prevention capabilities. Which cloud networking security service is BEST suited for this purpose?

  1. ANetwork Access Control List (NACL)
  2. BVirtual Private Cloud (VPC) flow logs
  3. CContent Delivery Network (CDN)
  4. DIntrusion Detection/Prevention System (IDS/IPS)
Show answer & explanation

Correct answer: D. Intrusion Detection/Prevention System (IDS/IPS)

An IDS/IPS provides deep packet inspection and intrusion prevention, actively identifying and blocking malicious traffic based on signatures and behavioral analysis, which aligns with the requirement for inspecting and preventing malicious content and exfiltration for a critical database.

Why the other options are wrong

  • A. NACLs are stateless firewalls that permit or deny traffic based on IP addresses, ports, and protocols, but lack deep packet inspection or IPS capabilities.
  • B. VPC flow logs record network traffic metadata (source, destination, port) but do not perform deep packet inspection or intrusion prevention.
  • C. CDNs are used to deliver content efficiently by caching it closer to users and do not provide network inspection or intrusion prevention capabilities.

Intrusion Detection/Prevention System (IDS/IPS)

A security system that monitors network traffic for suspicious activity and can either alert on (IDS) or actively block (IPS) threats based on predefined rules or anomaly detection.

  • Performs deep packet inspection.
  • Can operate in detection (IDS) or prevention (IPS) modes.
  • Critical for protecting sensitive networks from known and unknown threats.

Memory trick: IDS/IPS: The vigilant guard that looks inside the packages.

More Security questions