AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringEasy

A security engineer is investigating a potential compromise of an AWS EC2 instance. The instance was observed making outbound connections to an unknown IP address on a non-standard port. The engineer needs to quickly identify all network traffic to and from this specific EC2 instance, including source/destination IP addresses, ports, protocols, and action (ALLOW/REJECT). Which AWS service should the engineer leverage to obtain this detailed network flow information?

  1. AVPC Flow Logs
  2. BAmazon GuardDuty
  3. CAWS CloudTrail
  4. DAWS Config
Show answer & explanation

Correct answer: A. VPC Flow Logs

VPC Flow Logs capture detailed information about IP traffic going to and from network interfaces in a VPC, which is exactly what's needed to investigate the EC2 instance's network activity.

Why the other options are wrong

  • B. Amazon GuardDuty is a threat detection service that monitors for malicious activity, but it doesn't provide raw network flow logs directly.
  • C. AWS CloudTrail records API calls and events in AWS, not network flow data.
  • D. AWS Config enables you to assess, audit, and evaluate the configurations of your AWS resources, not network traffic.

VPC Flow Logs

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC.

  • Monitors network traffic in VPCs
  • Records source/destination IP, port, protocol, action
  • Helps with security analysis and troubleshooting

Memory trick: Flowing traffic in my VPC, logs for all to see.

More Domain 2: Logging and Monitoring questions