AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsHard
A global enterprise has several applications deployed on Amazon EC2 instances within a single VPC. They need to enforce strict outbound traffic filtering rules, such as blocking access to specific malicious IP addresses, preventing data exfiltration to unauthorized domains, and inspecting all egress traffic for compliance. The current solution uses security groups and network ACLs, which are insufficient for deep packet inspection and URL-based filtering. The company requires a centralized, managed solution that can be applied across all subnets in the VPC without deploying and managing individual proxy servers or firewalls on each EC2 instance. Which AWS service should the Solutions Architect recommend?
- AAWS Network Firewall
- BAWS Shield Advanced
- CAWS WAF (Web Application Firewall)
- DAmazon GuardDuty
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Network Firewall
AWS Network Firewall is a managed network security service that provides fine-grained network traffic inspection and filtering for VPCs. It allows for centralized enforcement of egress filtering rules, including blocking specific IP addresses and domains, and integrates with Suricata-compatible rule engines for deep packet inspection.
Why the other options are wrong
- B. AWS Shield Advanced is a managed DDoS protection service. It protects against large-scale denial-of-service attacks and does not provide granular outbound traffic filtering capabilities.
- C. AWS WAF protects web applications from common web exploits. It operates at Layer 7 (HTTP/S) and is not suitable for general outbound traffic filtering across all protocols and layers within a VPC.
- D. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior. It does not actively block or filter traffic based on defined rules.
AWS Network Firewall
A managed service that makes it easy to deploy, set up, and scale network security across all of your Amazon VPCs. It provides stateful inspection, intrusion prevention, and web filtering.
- Centralized network traffic inspection and filtering.
- Supports Suricata-compatible rules for deep packet inspection.
- Enforces fine-grained ingress and egress traffic policies.
Memory trick: Network Firewall is the bouncer for your VPC, checking every packet in and out.