AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsHard
A large enterprise has several applications deployed on Amazon EC2 instances within a single VPC. The security team requires granular, centralized network traffic inspection and filtering for both ingress and egress traffic, including stateful inspection and intrusion prevention capabilities, across all subnets and applications in the VPC. They want to simplify network security management and ensure compliance with regulatory requirements. Which AWS service should they implement?
- AAWS Network Firewall
- BVPC Flow Logs with AWS GuardDuty
- CSecurity Groups
- DNetwork Access Control Lists (NACLs)
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Network Firewall
AWS Network Firewall is a fully managed service that provides granular network traffic inspection and filtering, including stateful inspection, intrusion prevention, and web filtering, across all VPC traffic. It simplifies centralized network security management for compliance and security posture improvement.
Why the other options are wrong
- B. VPC Flow Logs capture network traffic metadata for monitoring and auditing, and GuardDuty provides threat detection, but neither actively inspects or filters live traffic for prevention.
- C. Security Groups are stateful and operate at the instance level, but they are distributed and not centralized for VPC-wide granular inspection and intrusion prevention.
- D. NACLs are stateless and operate at the subnet level, providing basic packet filtering but lacking the advanced stateful and intrusion prevention features required.
AWS Network Firewall
A fully managed network security service that provides granular network traffic inspection and filtering at the VPC level.
- Offers stateful inspection, intrusion prevention, and web filtering.
- Centralized control for all VPC traffic.
- Integrates with AWS Transit Gateway for multi-VPC deployments.
Memory trick: Network Firewall is the highly trained security guard at the VPC entrance and exit, checking every packet.