PrepAway - Latest Free Exam Questions & Answers

Which of the following options would you consider?

You are designing an intrusion detection prevention (IDS/IPS) solution for a customer web application in a
single VPC. You are considering the options for implementing IOS IPS protection for traffic coming from the
Internet.
Which of the following options would you consider? (Choose 2 answers)

PrepAway - Latest Free Exam Questions & Answers

A.
Implement IDS/IPS agents on each Instance running In VPC

B.
Configure an instance in each subnet to switch its network interface card to promiscuous mode and analyze
network traffic.

C.
Implement Elastic Load Balancing with SSL listeners In front of the web applications

D.
Implement a reverse proxy layer in front of web servers and configure IDS/IPS agents on each reverse proxy
server.

4 Comments on “Which of the following options would you consider?

  1. KwagongMakisig says:

    Yes A & D.
    EC2 does not allow promiscuous mode, and you cannot put something in between the ELB and the web server (like a listener or IDP)




    0



    1

Leave a Reply

Your email address will not be published. Required fields are marked *