AWS Certified Advanced Networking – Specialty (ANS-C01) — Question 102

A company has an application that runs on a fleet of Amazon EC2 instances. A new company regulation mandates that all network traffic to and from the EC2 instances must be sent to a centralized third-party EC2 appliance for content inspection.

Which solution will meet these requirements?

Answer options

Correct answer: B

Explanation

Option B is correct because it directly addresses the requirement to send all network traffic to a centralized appliance using a mirror session, allowing real-time content inspection. Options A and D involve flow logs, which do not provide real-time traffic inspection. Option C, while using a mirror session, incorrectly relies on Kinesis Data Firehose, which is not appropriate for real-time traffic inspection.