🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 9 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your company runs a highly available REST API on Amazon EC2 instances behind an Application Load Balancer in a VPC spanning two Availability Zones. The security team must add an intrusion detection capability that can automatically analyze VPC traffic to identify activities such as port scans and cryptocurrency mining without you having to deploy or maintain additional monitoring infrastructure. Which AWS option best meets these requirements?

  • Turn on VPC Flow Logs for all subnets and create CloudWatch metric filters and alarms for known malicious IP addresses and ports.

  • Use VPC Traffic Mirroring to forward all traffic to self-managed Suricata IDS instances running in a separate monitoring VPC.

  • Deploy AWS Network Firewall with managed threat signature rules to inspect all outbound and inbound traffic.

  • Enable Amazon GuardDuty for the AWS account and configure findings to send alerts to Amazon CloudWatch Events.

ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot