AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsHard

A large enterprise has several applications deployed on Amazon EC2 instances within a single VPC. The security team has identified a need to implement granular network traffic inspection and filtering at the VPC boundary for both inbound and outbound traffic, including stateful inspection, intrusion prevention (IPS), and intrusion detection (IDS). This must be centrally managed and applied consistently across multiple subnets and workloads, without requiring the deployment and management of individual security appliances on EC2 instances. Which AWS service should a Solutions Architect recommend?

  1. AAmazon GuardDuty
  2. BAWS Network Firewall
  3. CNetwork Access Control Lists (NACLs)
  4. DAWS WAF (Web Application Firewall)
Show answer & explanation

Correct answer: B. AWS Network Firewall

AWS Network Firewall is a fully managed service that makes it easier to deploy, maintain, and scale network protections across all of your Amazon VPCs. It provides stateful inspection, intrusion prevention system (IPS), and web filtering, allowing granular control over network traffic at the VPC boundary, centrally managed, without the operational burden of self-managed firewalls.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service that continuously monitors for malicious activity and unauthorized behavior. It is a detective control, not a preventative network firewall that inspects and filters traffic at the VPC boundary.
  • C. NACLs are stateless packet filters that operate at the subnet level. They provide basic inbound/outbound rules but lack stateful inspection, IPS/IDS capabilities, or the centralized management features required for advanced network security.
  • D. AWS WAF is a web application firewall that protects web applications from common web exploits. It operates at Layer 7 (HTTP/HTTPS) and is not suitable for granular network traffic inspection, stateful inspection, or IPS/IDS at the VPC boundary for all traffic types.

AWS Network Firewall

A fully managed network security service that provides intrusion prevention and detection, stateful inspection, and web filtering for all traffic entering or leaving your VPCs.

  • Fully managed, scales automatically.
  • Stateful inspection of network traffic.
  • Includes Intrusion Prevention System (IPS) and Intrusion Detection System (IDS).
  • Centrally managed across multiple VPCs/subnets.

Memory trick: Network Firewall is the 'VPC Border Patrol', inspecting every packet with advanced tools.

More Continuously Improve Existing Solutions questions