AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A large healthcare organization utilizes AWS for hosting sensitive patient data and applications. Due to strict HIPAA compliance requirements, all network traffic within their VPCs and between VPCs must be inspected for malicious activity and unauthorized data exfiltration. They need a scalable, managed solution that can be centrally deployed and enforced across multiple VPCs and AWS accounts. Which AWS service is best suited for this requirement?
- AAWS Network Firewall
- BAWS GuardDuty
- CAWS Firewall Manager
- DVPC Endpoint Services
Show answer & explanationAnswer & explanation
Correct answer: A. AWS Network Firewall
AWS Network Firewall is a managed service that provides intrusion prevention and detection, URL filtering, and stateful inspection for VPC traffic. It can be centrally managed and deployed across multiple VPCs via AWS Firewall Manager, making it ideal for the described scenario.
Why the other options are wrong
- B. AWS GuardDuty is a threat detection service that monitors for malicious activity but doesn't provide active traffic inspection or prevention.
- C. AWS Firewall Manager helps centrally configure and manage firewall rules across accounts/VPCs but doesn't provide the firewall inspection capabilities itself.
- D. VPC Endpoint Services allow private access to services within AWS and do not provide network traffic inspection or prevention.
AWS Network Firewall
A managed firewall service that provides network intrusion prevention and detection, URL filtering, and stateful packet inspection for all traffic traversing a VPC.
- Managed, highly available service.
- Stateful inspection, IPS/IDS, URL filtering.
- Deployed at the subnet level.
- Can be centrally managed with AWS Firewall Manager.
Memory trick: Network Firewall is the watchful 'bouncer' at every VPC's door, centrally managed.