AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A network administrator suspects that an EC2 instance is communicating with an unusual external IP address and wants to capture metadata about IP traffic going to and from the instance's network interface, including source, destination, and port information. Which AWS feature should be used?
- AAmazon VPC Flow Logs
- BAWS Config resource relationship view
- CAWS CloudTrail management events
- DAmazon Inspector network reachability analysis
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon VPC Flow Logs
VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, including source/destination IP, ports, protocol, and accept/reject decisions, making them ideal for investigating suspicious network activity.
Why the other options are wrong
- B. Config tracks resource configuration changes, not traffic data
- C. CloudTrail records API calls, not network packet-level traffic metadata
- D. Inspector's network reachability checks configuration paths, not live traffic
VPC Flow Logs
A feature that captures metadata about IP traffic flowing to and from network interfaces within a VPC.
- Can be enabled at VPC, subnet, or ENI level
- Captures source/destination IP, port, protocol, and action (accept/reject)
- Logs can be sent to CloudWatch Logs or S3 for analysis
Memory trick: Flow Logs are the traffic camera watching every packet's path.