AWS Certified SysOps Administrator – AssociateMonitoring, Logging, and RemediationEasy
A SysOps administrator needs to analyze network traffic flowing to and from Amazon EC2 instances within a VPC to diagnose connectivity issues and identify potential security risks. Which AWS feature should they enable to capture detailed information about IP traffic?
- AAWS Config
- BVPC Flow Logs
- CAWS CloudTrail
- DAmazon CloudWatch Logs
Show answer & explanationAnswer & explanation
Correct answer: B. VPC Flow Logs
VPC Flow Logs capture detailed information about the IP traffic going to and from network interfaces in your VPC. This data is crucial for troubleshooting network connectivity, analyzing traffic patterns, and identifying security threats.
Why the other options are wrong
- A. AWS Config monitors resource configurations, not active network traffic.
- C. AWS CloudTrail records API calls and events, not network traffic.
- D. Amazon CloudWatch Logs is a destination for logs but not the source for network traffic details itself.
VPC Flow Logs
A feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.
- Records accepted and rejected network traffic.
- Logs include source/destination IP, port, protocol, action, and bytes transferred.
- Can be published to CloudWatch Logs, S3, or Kinesis Data Firehose.
Memory trick: Flow Logs show the traffic's 'flow' through the VPC.