🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A security engineer must deploy an intrusion detection capability inside an Amazon VPC that contains two private subnets for application servers and one public subnet for NAT gateways. Compliance requires that all outbound traffic generated by the application servers be inspected, but performance overhead on the traffic path must be minimized. Which approach best satisfies these requirements while aligning with proper network-device placement principles?

  • Replace the NAT gateways with a self-managed proxy server running the IDS, and configure the private subnet route tables to forward 0.0.0.0/0 through that proxy.

  • Create an AWS Network Firewall in each private subnet, update the route tables so all egress traffic flows through the firewall, and install the IDS behind it for inspection.

  • Deploy an interface VPC endpoint to the IDS appliance and require application servers to send outbound traffic through this endpoint for inspection.

  • Enable VPC Traffic Mirroring on the application servers' elastic network interfaces and direct the mirrored traffic to an IDS appliance in a dedicated monitoring subnet.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot