ANS-C01 exam dumps

ANS-C01 practice question 378 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 378

Select 3

A company has deployed a web application in a VPC. They are experiencing intermittent connectivity issues, and the security team wants to analyze the traffic to identify potential network misconfigurations or malicious activities. Which combination of AWS tools should the team use to collect and analyze the required data?

  1. A

    Amazon CloudWatch to monitor metrics and set up alarms for unusual traffic patterns

  2. B

    VPC Flow Logs to capture IP-level traffic data between resources in the VPC

  3. C

    AWS Trusted Advisor to provide recommendations on VPC configuration

  4. D

    VPC Traffic Mirroring to capture and inspect packet-level traffic in real time

  5. E

    Amazon Inspector to perform a vulnerability assessment on the resources in the VPC

Show answer and explanation

Correct answers: A, B, D

Explanation

To analyze intermittent connectivity issues and potential malicious activities, the security team needs tools that provide both high-level and in-depth traffic data. Amazon CloudWatch can monitor traffic metrics and alert on unusual patterns, while VPC Flow Logs capture IP-level traffic data for analysis. VPC Traffic Mirroring goes a step further by allowing real-time inspection of packet-level traffic, enabling a thorough investigation. AWS Trusted Advisor and Amazon Inspector serve different purposes and are not suitable for this use case.

  • A. Correct.

    Amazon CloudWatch is useful for monitoring metrics such as network throughput and setting up alarms to detect unusual traffic patterns, which can assist in identifying intermittent connectivity issues.

  • B. Correct.

    VPC Flow Logs capture IP-level traffic data, including source and destination IPs, ports, and protocols, which is essential for analyzing network traffic and troubleshooting connectivity issues.

  • C. Incorrect.

    AWS Trusted Advisor provides best-practice recommendations for optimizing resources, security, and configurations, but it does not capture or analyze network traffic directly.

  • D. Correct.

    VPC Traffic Mirroring allows you to capture packet-level traffic for a specific network interface in the VPC, which is crucial for in-depth inspection and identifying potential malicious activities.

  • E. Incorrect.

    Amazon Inspector is designed for automated security assessments and vulnerability scanning, but it is not used for capturing or analyzing network traffic.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam