AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringHard
A security team is implementing a custom intrusion detection system (IDS) on an EC2 instance. This IDS needs to analyze network traffic in real-time for suspicious patterns. The EC2 instance must have access to all network traffic flowing through its associated network interface, not just traffic destined for the instance itself. Which feature should be enabled on the EC2 instance's network interface to achieve this?
- AEnable source/destination check.
- BAttach a secondary network interface.
- CEnable VPC Flow Logs.
- DConfigure Traffic Mirroring to send traffic to the IDS instance.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure Traffic Mirroring to send traffic to the IDS instance.
Traffic Mirroring allows you to copy network traffic from an elastic network interface (ENI) of an EC2 instance and send it to another EC2 instance (the IDS) for analysis. This provides the IDS instance with a copy of all relevant traffic, not just its own, which is essential for an IDS.
Why the other options are wrong
- A. Source/destination check is typically disabled on NAT instances or gateways, allowing them to send/receive traffic for other instances, but it doesn't copy all traffic to an IDS.
- B. Attaching a secondary network interface doesn't inherently provide a copy of all traffic for an IDS; it just provides another interface.
- C. VPC Flow Logs record metadata about network traffic (source/destination IP, port, protocol) but do not provide the actual packet content that an IDS would need for deep-packet inspection.
VPC Traffic Mirroring
A feature that allows you to copy network traffic from an Elastic Network Interface (ENI) and send it to a monitoring tool for deep packet inspection.
- Copies actual network packets
- Used for security monitoring, anomaly detection, troubleshooting
- Targets can be EC2 instances or Network Load Balancers
Memory trick: Mirror the traffic, catch the bad actors.