AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy

A security operations center (SOC) team is investigating a potential data exfiltration attempt from an Amazon EC2 instance within a VPC. They suspect that an attacker gained access and is communicating with an external malicious IP address. To confirm this, they need to analyze network traffic flow data, including source/destination IP addresses, ports, protocols, and traffic volume. Which AWS logging solution provides this specific type of information?

  1. AVPC Flow Logs
  2. BAWS WAF logs
  3. CAWS CloudTrail logs
  4. DAmazon S3 access logs
Show answer & explanation

Correct answer: A. VPC Flow Logs

VPC Flow Logs capture detailed information about IP traffic going to and from network interfaces in a VPC. This includes source/destination IP addresses, ports, protocols, and bytes transferred, which is crucial for investigating network-level data exfiltration attempts.

Why the other options are wrong

  • B. AWS WAF logs record web requests that AWS WAF inspects, which is for web application traffic, not general VPC network traffic.
  • C. CloudTrail logs administrative and management events (API calls), not network traffic flow.
  • D. S3 access logs record requests made to an S3 bucket, not network traffic within a VPC.

VPC Flow Logs

A feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.

  • Records source/destination IP, port, protocol, action (ACCEPT/REJECT), bytes, packets.
  • Can be published to Amazon CloudWatch Logs or Amazon S3.
  • Useful for network troubleshooting, security analysis, and compliance.

Memory trick: VPC Flow Logs show network's ebb and flow, where data dares to go.

More Domain 2: Logging and Monitoring questions