CompTIA Cloud Essentials+ (CLO-002)Management and Technical OperationsHard
A cloud operations team is investigating unexpected high network egress costs from a particular Virtual Private Cloud (VPC). They suspect an unauthorized or misconfigured application is sending large amounts of data outside the cloud provider's network. Which cloud service or feature would be most effective for identifying the source and destination of this unexpected traffic?
- AVirtual Machine (VM) console access
- BVPC Flow Logs
- CCloud Load Balancer logs
- DCloud Storage access logs
Show answer & explanationAnswer & explanation
Correct answer: B. VPC Flow Logs
VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC. This data includes source/destination IP addresses, ports, protocols, and the amount of data transferred, making it ideal for identifying unauthorized egress traffic.
Why the other options are wrong
- A. VM console access allows interaction with a single VM but doesn't provide a consolidated view of network traffic across the entire VPC.
- C. Load balancer logs show traffic to/from the load balancer, but not necessarily all egress from the VPC, especially if applications bypass it.
- D. Cloud storage access logs show who accessed storage objects, not the network traffic patterns of compute instances.
VPC Flow Logs
A feature that captures information about the IP traffic going to and from network interfaces in a Virtual Private Cloud (VPC).
- Records source/destination IP, port, protocol, bytes, packets.
- Used for network monitoring, security analysis, and troubleshooting.
- Can be published to various storage and analytics services.
Memory trick: Flow logs show who's going where, load balancer knows who comes by, storage logs who touched the file, VM console is just one guy.