🔍

AWS Certified Advanced Networking - Specialty ANS-C01 — Question 61

Topic 1 · Question 61 of 292

Topic 1 · Question 61

A company has deployed an application in a VPC that uses a NAT gateway for outbound traffic to the internet. A network engineer notices a large quantity of suspicious network traffic that is traveling from the VPC over the internet to IP addresses that are included on a deny list. The network engineer must implement a solution to determine which AWS resources are generating the suspicious traffic. The solution must minimize cost and administrative overhead. Which solution will meet these requirements?