Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium
A cloud security team is implementing a new Intrusion Detection System (IDS) for their virtual network infrastructure. They need to analyze traffic flowing between different virtual machines (VMs) within the same virtual network, as well as traffic leaving and entering the virtual network from the internet. Which cloud networking feature is essential for enabling the IDS to passively monitor all relevant network traffic?
- AVirtual Private Network (VPN) Gateway
- BDirect Connect
- CNetwork Address Translation (NAT) Gateway
- DTraffic Mirroring (Port Mirroring)
Show answer & explanationAnswer & explanation
Correct answer: D. Traffic Mirroring (Port Mirroring)
Traffic Mirroring (often called port mirroring or SPAN in traditional networks) allows the duplication of network traffic from source network interfaces to a destination monitoring interface, enabling an IDS to passively analyze all traffic without being in the direct data path.
Why the other options are wrong
- A. VPN gateways establish encrypted tunnels for secure connectivity, not for passive traffic analysis.
- B. Direct Connect provides a dedicated private connection to the cloud, not a feature for internal traffic monitoring.
- C. NAT gateways translate IP addresses for outbound internet traffic, not for traffic monitoring.
Traffic Mirroring (Cloud)
A cloud networking feature that copies network traffic from a source (e.g., VM network interface) to a destination (e.g., another VM, network interface, or network load balancer) for monitoring and analysis.
- Enables passive monitoring of network traffic.
- Essential for IDS/IPS, network forensics, and performance monitoring.
- Similar to traditional network 'port mirroring' or 'SPAN'.
Memory trick: Traffic Mirroring is like having a security camera for your network packets.