AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationEasy

A SysOps administrator needs to monitor the network performance and security of an Amazon VPC. Specifically, they want to log all accepted and rejected IP traffic flows to and from network interfaces in the VPC for forensic analysis and troubleshooting connectivity issues. Which AWS service should be enabled?

  1. AAmazon GuardDuty
  2. BAWS CloudTrail
  3. CVPC Flow Logs
  4. DAWS Network Firewall
Show answer & explanation

Correct answer: C. VPC Flow Logs

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in your VPC. They provide a detailed record of accepted and rejected traffic, including source/destination IP addresses, ports, protocols, and action (ACCEPT/REJECT), which is invaluable for network troubleshooting and security analysis.

Why the other options are wrong

  • A. Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, but it doesn't provide raw IP traffic flow logs for general forensic analysis.
  • B. CloudTrail logs API calls made to AWS services, not the actual IP traffic flowing within a VPC.
  • D. AWS Network Firewall is a managed firewall service for filtering traffic, not a logging service for all accepted/rejected IP traffic flows.

VPC Flow Logs

VPC Flow Logs capture information about the IP traffic that goes to and from network interfaces in your VPC. They help you monitor and troubleshoot network connectivity and security within your AWS environment.

  • Records metadata about IP traffic flows.
  • Includes source/destination IP, port, protocol, action (ACCEPT/REJECT).
  • Can be published to CloudWatch Logs or S3 for analysis.

Memory trick: Flow Logs see all the traffic moving through the VPC's rivers.

More Monitoring, Logging, and Remediation questions