Q: 3
Gathering business requirements can aid the organization in determining all of this information about organizational assets, except:
Options
Discussion
A not B. NSGs (B) only filter ports and IPs, they don't actually inspect packet contents like DPI does.
A imo, DPI at the application level is what shows up in practice and exam reports.
Its A here. DPI gives actual application layer inspection, not just port/IP filtering like NSGs. Pretty sure that’s what compliance needs.
A , that's what most practice exams and official guides point to for cloud traffic inspection.
B , I think NSGs with rules are enough here for inspection since they manage traffic flows well in cloud environments.
I don't think B is right here, it's kind of a trap since NSGs just do basic filtering. A is the better fit because DPI actually looks into the payload, which is what you want for sensitive cloud-native app traffic. If the data was always encrypted end-to-end, maybe we'd have to rethink it, but with standard cloud setups, pretty sure A wins out.
I get why A is chosen here. DPI at the application layer can actually look into the payload, so it’s way more effective for cloud-native apps handling sensitive data. NSGs (B) just work at network/port level, not deep enough for compliance needs. Pretty sure A is the right move unless we can't see decrypted traffic.
A tbh, seen similar recommendations in official ISC2 guides and practice test explanations too.
Makes sense to me, A fits best for proper inspection of app traffic in the cloud. DPI's what you want here.
C or D. Not convinced A is always possible in cloud-native, especially if traffic stays encrypted. DPI feels like a trap here.
Be respectful. No spam.