A BGP-based AWS VPN connects on-premises to a VPC. The developer can reach an EC2 instance in subnet A but cannot reach one in subnet B within the same VPC. Which logs will show whether traffic is reaching subnet B?
Choose an answer
Tap an option to check your answer.
Correct answer: VPC Flow Logs.
Why this is the answer
VPC Flow Logs capture IP traffic going to and from network interfaces in your VPC, including traffic that is blocked by security groups or network ACLs. This makes them ideal for diagnosing connectivity issues between subnets, as they will show whether traffic is reaching the network interface in subnet B and what action (ACCEPT or REJECT) was taken. VPN logs focus on the VPN tunnel status and connection, not individual packet flow within the VPC. BGP logs are for routing protocol information, not traffic flow within the VPC. AWS CloudTrail logs API calls and management events, not network traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed