Configure VPC Traffic Mirroring to copy packets to an IDS monitoring instance

Answer Correct answer: C — VPC Traffic Mirroring copies full packets to the monitoring EC2 instance for IDS inspection.

A company hosts an application on Amazon EC2 that is subject to specific rules for regulatory compliance. One rule states that traffic to and from the workload must be inspected for network-level attacks. This involves inspecting the whole packet. To comply with this regulatory rule, a security engineer must install intrusion detection software on a c5n.4xlarge EC2 instance. The engineer must then configure the software to monitor traffic to and from the application instances. What should the security engineer do next?

  1. Place the network interface in promiscuous mode to capture the traffic
  2. Configure VPC Flow Logs to send traffic to the monitoring EC2 instance using a Network Load Balancer.
  3. Configure VPC traffic mirroring to send traffic to the monitoring EC2 instance using a Network Load Balancer. Correct Answer
  4. Use Amazon Inspector to detect network-level attacks and trigger an AWS Lambda function to send the suspicious packets to the EC2 instance.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

VPC Traffic Mirroring is the purpose-built feature for sending a copy of all packets to a monitoring target (here an NLB-fronted IDS instance). Promiscuous mode (A) is a step on the NIC but does not deliver traffic from other instances; VPC Flow Logs (B) are metadata summaries, not full payloads, so they cannot feed an IDS doing deep packet inspection; Inspector (D) is vulnerability scanning, not a network tap.

A regulatory rule requires whole-packet inspection (promiscuous/IDS) of traffic to and from an EC2 workload. VPC Traffic Mirroring copies (mirrors) the network traffic from the application instances' ENIs to a monitoring EC2 instance running IDS software, enabling full packet capture and analysis without altering the production path.

Picking VPC Flow Logs (B)—they capture flow records (metadata), not full packet payloads, so an IDS cannot do deep packet inspection on them. Choosing promiscuous mode alone (A) without a mirroring mechanism does not bring peer traffic to the IDS instance. Inspector (D) scans hosts, not network traffic.

Community Discussion (3 comments)

navid1365 👍 2 Selected: C
C : VPC Traffic Mirroring: https://aws.amazon.com/blogs/aws/new-vpc-traffic-mirroring/
Certified101 👍 3 Selected: C
C is correct
Zek 👍 2
C: https://aws.amazon.com/blogs/aws/new-vpc-traffic-mirroring/ Also see discussions here https://www.examtopics.com/discussions/amazon/view/47597-exam-aws-certified-security-specialty-topic-1-question-228/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

VPC Traffic Mirroring is the AWS feature designed to copy a replica of network traffic from source ENIs to a monitoring destination, such as an IDS instance behind a Network Load Balancer. It delivers full packets (whole-packet inspection) without changing the production traffic path, satisfying the regulatory requirement.

Why the Other Options Are Wrong

A (promiscuous mode) is a NIC setting but by itself does not deliver peer traffic to the monitoring instance. B (VPC Flow Logs) exports metadata flow records, not payloads, so it cannot support deep packet inspection. D (Inspector) is host vulnerability scanning, not network tapping. C is the correct mechanism.

Community Comment Notes

Community voted C (100). Commenters linked the VPC Traffic Mirroring launch blog and confirmed it is the mechanism to mirror traffic to a monitoring instance. B's Flow Logs limitation (metadata only) was noted.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide