A consulting firm manages AWS accounts for customers. One customer needs intrusion prevention added without re-architecting. The customer's environment has five VPCs across two US Regions connected by VPC peering and they do not plan to add more VPCs in the next 2 years. The solution must be able to inspect unencrypted traffic. Which approach satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use an AWS Network Firewall distributed deployment model in each VPC..
Why this is the answer
The correct answer is to use an AWS Network Firewall distributed deployment model in each VPC. AWS Network Firewall provides intrusion prevention system (IPS) capabilities and can inspect unencrypted traffic. A distributed deployment, where a firewall endpoint is placed in each VPC, allows for granular inspection within each VPC without requiring re-architecture of the existing VPC peering connections. This approach is suitable for a fixed number of VPCs and avoids the complexity of routing all traffic through a central inspection VPC, which would be necessary for a centralized model and would break existing peering. Incorrect options: VPC security groups and network ACLs offer stateful and stateless packet filtering, respectively, but do not provide intrusion prevention capabilities. A centralized AWS Network Firewall deployment would require re-architecting the network to route all inter-VPC traffic through a central inspection VPC, which is explicitly ruled out by the requirement to avoid re-architecting. AWS Shield provides DDoS protection and does not offer intrusion prevention or deep packet inspection for unencrypted traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed