Courseiva
hardMultiple ChoiceObjective-mapped

350-701 Practice Question: Uses AWS with a VPC and wants to inspect all…

An organization uses AWS with a VPC and wants to inspect all traffic between instances in the same subnet using Cisco Firepower. What must be implemented?

⚠ Common exam trap

Cisco often tests the misconception that you can deploy a transparent bridge or inline firewall within a VPC subnet, but AWS does not support Layer 2 bridging; Traffic Mirroring is the only way to achieve out-of-band inspection for intra-subnet traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS Traffic Mirroring to send traffic to a Firepower appliance

AWS Traffic Mirroring captures and forwards network traffic from Elastic Network Interfaces (ENIs) to a security appliance, such as a Cisco Firepower instance, for inspection. This allows the organization to monitor all traffic between instances within the same subnet without requiring changes to the routing table or placing the Firepower inline, which is not possible in a VPC without a gateway appliance. Option B is correct because Traffic Mirroring is the native AWS feature designed for out-of-band traffic inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure VPC Endpoints to route traffic through Firepower

    Why it's wrong here

    VPC Endpoints are for accessing AWS services, not for inspecting east-west traffic.

  • AWS Traffic Mirroring to send traffic to a Firepower appliance

    Why this is correct

    Traffic Mirroring copies packets to Firepower for east-west inspection.

  • Use AWS Security Groups and log to Firepower

    Why it's wrong here

    Security Groups are stateful firewalls but cannot send logs to Firepower for inspection.

  • Deploy Firepower as a transparent bridge in the subnet

    Why it's wrong here

    Transparent bridging is not supported in AWS; traffic must be mirrored.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.