Lumen AI wants to prevent data exfiltration from its VPC by blocking outbound HTTPS to known malicious domains and also detect internal port scans. They prefer a managed, inline inspection service. Which solution best meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create AWS Network Firewall stateful rule groups: a domain list/Suricata rule group to block FQDNs via TLS SNI/HTTP Host and a Suricata ruleset to detect port scans; attach them to a firewall policy and route outbound traffic through the firewall subnets..
Why this is the answer
AWS Network Firewall is the best solution because it offers inline, managed network security with stateful inspection. You can create stateful rule groups, including domain lists for FQDN blocking via TLS SNI or HTTP Host headers, effectively preventing data exfiltration to malicious domains. Additionally, Network Firewall supports Suricata-compatible rules, allowing you to define custom rulesets to detect internal port scans. Routing outbound traffic through firewall subnets ensures all relevant traffic is inspected. Security groups operate at the instance level and only allow or deny traffic based on IP addresses and ports, not FQDNs or advanced threat detection like port scans. AWS WAF is designed for web applications and protects against common web exploits, not general outbound network traffic or port scanning within a VPC. Route 53 Resolver DNS Firewall blocks DNS queries to malicious domains but does not inspect L3/L4 traffic for port scans.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed