Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityHard

An organization is deploying a new application to a public cloud provider and needs to ensure that all network traffic between different virtual machines (VMs) within the same virtual private cloud (VPC) is inspected for malicious activity. Which cloud security technology is best suited to perform deep packet inspection and intrusion prevention for this East-West traffic?

  1. ALoad Balancer
  2. BVirtual Network Firewall (VNF)
  3. CSecurity Group (SG)
  4. DNetwork Access Control List (NACL)
Show answer & explanation

Correct answer: B. Virtual Network Firewall (VNF)

A Virtual Network Firewall (VNF), often deployed as a next-generation firewall (NGFW) appliance in the cloud, is specifically designed to perform deep packet inspection, stateful inspection, and intrusion prevention for both North-South and East-West traffic within a cloud environment.

Why the other options are wrong

  • A. Load Balancers distribute traffic and may offer some basic security, but do not perform deep packet inspection or intrusion prevention.
  • C. Security Groups are stateful firewalls at the instance level but also lack deep packet inspection and intrusion prevention capabilities.
  • D. NACLs are stateless, operating at the subnet level, and only permit/deny traffic based on IP/port, without deep packet inspection.

Virtual Network Firewall (VNF)

A software-based firewall deployed within a cloud environment that provides advanced network security features, including deep packet inspection, stateful inspection, and intrusion prevention for virtual networks.

  • Offers capabilities similar to physical next-generation firewalls (NGFWs).
  • Can inspect traffic at layer 7 (application layer).
  • Crucial for securing East-West traffic within a cloud VPC.

Memory trick: For deep cloud traffic inspection, you need a smart firewall, not just a gate.

More Cloud Security questions