A company’s security policy requires all Amazon EC2 instances to use the Amazon Time Sync Service. AWS CloudTrail is enabled in all accounts, and VPC flow logs are enabled for all VPCs. The security engineer must identify any EC2 instances that attempt to use public NTP servers on the internet. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Monitor VPC flow logs for traffic to nonstandard NTP servers on the internet..
Why this is the answer
The correct answer is to monitor VPC flow logs for traffic to nonstandard NTP servers on the internet. VPC flow logs capture information about IP traffic going to and from network interfaces in your VPC. By analyzing these logs, you can identify instances attempting to connect to public NTP servers (typically UDP port 123) instead of the Amazon Time Sync Service. Monitoring CloudTrail logs for API calls to nonstandard time services is incorrect because CloudTrail records API calls made to AWS services, not network traffic originating from EC2 instances to external services. Similarly, monitoring CloudTrail logs for API calls to the Amazon Time Sync Service would only show if instances are trying to use the service, not if they are failing to use it and falling back to public NTP. Monitoring VPC flow logs for traffic to the Amazon Time Sync Service is also incorrect because the goal is to find instances not using the Amazon Time Sync Service and instead using public NTP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed