AWS Certified Security – SpecialtyDomain 1: Incident ResponseEasy

A security operations team is investigating a suspected data exfiltration attempt from an Amazon RDS database instance. They need to determine if any outbound connections were made from the RDS instance to suspicious external IP addresses. The RDS instance is configured with VPC Flow Logs enabled for its subnet. Which service should the team use to efficiently query and analyze these flow logs to identify potential exfiltration attempts?

  1. AAmazon CloudWatch Logs Insights.
  2. BAmazon Athena querying S3 logs.
  3. CAWS CloudTrail with advanced event selectors.
  4. DAmazon RDS Performance Insights.
Show answer & explanation

Correct answer: A. Amazon CloudWatch Logs Insights.

Amazon CloudWatch Logs Insights is specifically designed for interactively querying and analyzing log data, including VPC Flow Logs, stored in CloudWatch Logs. It provides a powerful query language to identify specific patterns like outbound connections to suspicious IPs.

Why the other options are wrong

  • B. While Amazon Athena can query S3 logs, VPC Flow Logs are typically sent to CloudWatch Logs. Using Athena would require exporting or configuring Flow Logs to S3, adding complexity compared to direct CloudWatch Logs Insights analysis.
  • C. CloudTrail logs AWS API calls, not network flow data from within a VPC, so it would not show outbound connections from an RDS instance.
  • D. RDS Performance Insights focuses on database performance metrics and SQL queries, not network flow logs.

VPC Flow Log Analysis

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in a VPC. CloudWatch Logs Insights is the primary tool for interactively querying and analyzing these logs for security investigations.

  • Records network flow data (source/destination IP, port, protocol).
  • Can be published to CloudWatch Logs or S3.
  • CloudWatch Logs Insights offers interactive query capabilities.

Memory trick: Logs Insights is the magnifying glass for your CloudWatch Logs.

More Domain 1: Incident Response questions