AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A large enterprise needs to implement a robust network intrusion detection and prevention system (IDPS) for its applications hosted on AWS. The solution must provide deep packet inspection, be highly scalable, and capable of protecting multiple VPCs across different AWS accounts. Which AWS service or architecture best meets these requirements?

  1. AUtilize AWS Network Firewall in conjunction with AWS Transit Gateway.
  2. BConfigure AWS WAF rules on Application Load Balancers for all web applications.
  3. CRely on Amazon GuardDuty for anomaly detection and network flow analysis.
  4. DDeploy open-source IDPS solutions on EC2 instances in each VPC.
Show answer & explanation

Correct answer: A. Utilize AWS Network Firewall in conjunction with AWS Transit Gateway.

AWS Network Firewall provides stateful inspection, intrusion prevention, and domain filtering, offering deep packet inspection capabilities. When combined with AWS Transit Gateway, traffic from multiple VPCs can be routed centrally through the Network Firewall, providing a highly scalable and centralized IDPS solution across accounts.

Why the other options are wrong

  • B. AWS WAF protects web applications at Layer 7 (HTTP/HTTPS) and prevents common web exploits. It does not provide network-wide IDPS for all traffic types across multiple VPCs.
  • C. Amazon GuardDuty is a threat detection service that monitors logs for malicious activity. It provides anomaly detection but does not offer inline, deep packet inspection or prevention capabilities like an IDPS.
  • D. Deploying open-source IDPS on EC2 instances in each VPC is complex to manage, scale, and maintain across many VPCs and accounts, and lacks centralized control.

Centralized IDPS with AWS Network Firewall and Transit Gateway

This architecture leverages AWS Network Firewall for deep packet inspection and intrusion prevention, and AWS Transit Gateway for centralizing traffic from multiple VPCs, enabling a scalable and robust IDPS solution across an organization.

  • AWS Network Firewall offers stateful firewall, IPS, and domain filtering.
  • AWS Transit Gateway centralizes routing for multi-VPC environments.
  • Provides deep packet inspection and prevention capabilities.

Memory trick: Network Firewall and TGW: The Centralized Security Watchtower.

More Network Security, Compliance, and Governance questions