A systems engineer is troubleshooting a test environment that includes an inline virtual security appliance. The development team also wants to use security groups and network ACLs to meet various security requirements. Which configuration change is required to allow the virtual security appliance to route traffic?
Choose an answer
Tap an option to check your answer.
Correct answer: Disable the source/destination check on the security appliance’s elastic network interface (ENI)..
Why this is the answer
The correct answer is to disable the source/destination check on the security appliance’s elastic network interface (ENI). By default, AWS instances perform a source/destination check, meaning they only send and receive traffic for their own IP address. A security appliance, acting as a router or firewall, needs to process traffic for other instances. Disabling this check allows the ENI to forward traffic not destined for its own IP, enabling the appliance to route traffic effectively. Disabling network ACLs is incorrect because network ACLs are a layer of security that can coexist with and complement a security appliance; they don't prevent routing. Configuring promiscuous mode is not directly applicable or configurable in this context for an AWS ENI. Placing the appliance in a public subnet with an internet gateway is incorrect because while it might be necessary for internet-facing traffic, it doesn't address the fundamental requirement of allowing the appliance to route traffic between other instances within the VPC.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed