A company must audit and log all outbound internet traffic originating in private subnets across multiple Regions and VPCs connected via Transit Gateway. They plan to use AWS Network Firewall and need full logging of all traffic for auditing and alerting. How should Network Firewall logging be configured to ensure complete capture of alerts and flows?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable Network Firewall's built-in logging to capture both alert events and flow logs..
Why this is the answer
Network Firewall's built-in logging captures both alert events (when a rule is matched) and flow logs (details about the traffic passing through the firewall). This comprehensive logging is essential for auditing and alerting, as it provides visibility into both security incidents and general traffic patterns. Enabling logging to Amazon CloudWatch for alerts only would miss the detailed flow information. VPC Flow Logs capture traffic at the ENI level, but Network Firewall's native flow logs provide more context specific to firewall processing. AWS CloudTrail logs API calls and management events, not data plane traffic or firewall alerts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed