A company with multiple accounts and VPCs in one Region must log all network traffic for EC2 and Amazon RDS, retain the logs for 12 months with infrequent access after 90 days, and include metadata fields such as vpc-id, subnet-id, and tcp-flags. Which lowest-cost solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable VPC Flow Logs with additional custom fields and store the logs in Amazon S3..
Why this is the answer
The correct option is to enable VPC Flow Logs with additional custom fields and store the logs in Amazon S3. VPC Flow Logs capture all IP traffic going to and from network interfaces, including EC2 and RDS instances. Custom fields allow the inclusion of metadata like vpc-id, subnet-id, and tcp-flags. Storing logs in Amazon S3 is cost-effective for long-term retention (12 months) and supports infrequent access, as S3 offers various storage classes like S3 Standard-IA or S3 Glacier for lower costs after 90 days. Storing logs in CloudWatch Logs (options 1 and 4) is generally more expensive for long-term storage and retrieval compared to S3, especially for large volumes of data and infrequent access. Traffic Mirroring (option 2) is designed for deep packet inspection and security analysis, not for general network traffic logging and retention, making it an overly complex and expensive solution for this requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed