AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy
A security operations center (SOC) team is investigating a potential data exfiltration attempt from an Amazon EC2 instance within a VPC. They suspect that an attacker gained access and is communicating with an external malicious IP address. To confirm this, they need to analyze network traffic flow data, including source/destination IP addresses, ports, protocols, and traffic volume. Which AWS logging solution provides this specific type of information?
- AVPC Flow Logs
- BAWS WAF logs
- CAWS CloudTrail logs
- DAmazon S3 access logs
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Flow Logs
VPC Flow Logs capture detailed information about IP traffic going to and from network interfaces in a VPC. This includes source/destination IP addresses, ports, protocols, and bytes transferred, which is crucial for investigating network-level data exfiltration attempts.
Why the other options are wrong
- B. AWS WAF logs record web requests that AWS WAF inspects, which is for web application traffic, not general VPC network traffic.
- C. CloudTrail logs administrative and management events (API calls), not network traffic flow.
- D. S3 access logs record requests made to an S3 bucket, not network traffic within a VPC.
VPC Flow Logs
A feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.
- Records source/destination IP, port, protocol, action (ACCEPT/REJECT), bytes, packets.
- Can be published to Amazon CloudWatch Logs or Amazon S3.
- Useful for network troubleshooting, security analysis, and compliance.
Memory trick: VPC Flow Logs show network's ebb and flow, where data dares to go.