Configure VPC Traffic Mirroring to copy packets to an IDS monitoring instance
A company hosts an application on Amazon EC2 that is subject to specific rules for regulatory compliance. One rule states that traffic to and from the workload must be inspected for network-level attacks. This involves inspecting the whole packet. To comply with this regulatory rule, a security engineer must install intrusion detection software on a c5n.4xlarge EC2 instance. The engineer must then configure the software to monitor traffic to and from the application instances. What should the security engineer do next?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
VPC Traffic Mirroring is the purpose-built feature for sending a copy of all packets to a monitoring target (here an NLB-fronted IDS instance). Promiscuous mode (A) is a step on the NIC but does not deliver traffic from other instances; VPC Flow Logs (B) are metadata summaries, not full payloads, so they cannot feed an IDS doing deep packet inspection; Inspector (D) is vulnerability scanning, not a network tap.
A regulatory rule requires whole-packet inspection (promiscuous/IDS) of traffic to and from an EC2 workload. VPC Traffic Mirroring copies (mirrors) the network traffic from the application instances' ENIs to a monitoring EC2 instance running IDS software, enabling full packet capture and analysis without altering the production path.
Picking VPC Flow Logs (B)—they capture flow records (metadata), not full packet payloads, so an IDS cannot do deep packet inspection on them. Choosing promiscuous mode alone (A) without a mirroring mechanism does not bring peer traffic to the IDS instance. Inspector (D) scans hosts, not network traffic.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.