AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A company is migrating a legacy application to AWS and needs to ensure that all network traffic, including internal VPC communications and external internet-bound traffic, is captured and sent to a centralized security information and event management (SIEM) system for deep packet inspection and anomaly detection. The SIEM is hosted on EC2 instances in a separate security VPC. What is the most efficient and scalable way to achieve this comprehensive network traffic capture?

  1. AEnable VPC Flow Logs for all VPCs and configure them to publish to Kinesis Data Firehose, then ingest into the SIEM.
  2. BDeploy a dedicated network agent on each EC2 instance to capture traffic and forward it to the SIEM.
  3. CConfigure AWS Network Firewall with logging enabled and send logs to the SIEM.
  4. DUse VPC Traffic Mirroring to mirror traffic from all relevant EC2 instances and ENIs to an EC2-based SIEM appliance.
Show answer & explanation

Correct answer: D. Use VPC Traffic Mirroring to mirror traffic from all relevant EC2 instances and ENIs to an EC2-based SIEM appliance.

VPC Traffic Mirroring allows you to copy network traffic from an Elastic Network Interface (ENI) of an EC2 instance and forward it to a monitoring destination, such as an EC2 instance running a SIEM or IDS. This enables deep packet inspection and comprehensive traffic analysis without agent deployment.

Why the other options are wrong

  • A. VPC Flow Logs provide metadata about IP traffic (source/dest IP, port, protocol, action) but not full packet contents for deep inspection.
  • B. Deploying agents on every instance is complex, resource-intensive, and difficult to manage at scale, especially for internal VPC traffic.
  • C. AWS Network Firewall inspects traffic passing through it and generates logs, but it does not capture internal VPC traffic between instances or provide full packet capture for deep inspection of all traffic.

VPC Traffic Mirroring

A feature that allows you to copy network traffic from an Elastic Network Interface (ENI) and send it to a monitoring destination for inspection.

  • Provides full packet capture for deep inspection.
  • Supports mirroring traffic from multiple ENIs to a single destination.
  • Useful for intrusion detection, anomaly detection, and compliance.

Memory trick: Mirror, Mirror on the VPC wall, show me the packets of them all.

More Domain 2: Logging and Monitoring questions