AWS Certified Security – SpecialtyDomain 2: Logging and MonitoringMedium

A security engineer is investigating a potential data exfiltration attempt from an EC2 instance that is part of a critical application. The attacker is suspected of trying to send data to an external malicious IP address. The engineer needs to analyze the network traffic originating from this specific EC2 instance to identify the destination IP addresses and ports. Which logging solution should the engineer primarily review?

  1. AVPC Flow Logs
  2. BAWS WAF logs
  3. CAWS CloudTrail logs
  4. DAmazon S3 access logs
Show answer & explanation

Correct answer: A. VPC Flow Logs

VPC Flow Logs capture information about the IP traffic going to and from network interfaces in a VPC. They record source and destination IP addresses, ports, and protocols, which are exactly the details needed to investigate potential data exfiltration by identifying external malicious IP addresses and the ports used from the compromised EC2 instance.

Why the other options are wrong

  • B. AWS WAF logs record traffic that passes through a Web Application Firewall, typically for HTTP/S traffic to web applications, not general outbound traffic from an EC2 instance.
  • C. AWS CloudTrail logs record API calls made to AWS services, not network traffic data from within a VPC.
  • D. Amazon S3 access logs record requests made to S3 buckets, not general network traffic from an EC2 instance.

VPC Flow Logs

A feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.

  • Records source/destination IP, port, protocol.
  • Helps diagnose network connectivity issues.
  • Crucial for security forensics and compliance.

Memory trick: Flow Logs are the network's detailed ledger, showing who talks to whom and how.

More Domain 2: Logging and Monitoring questions