A retail environment has ALBs in public subnets with backend EC2 instances in private subnets that use a NAT gateway for outbound internet calls. NAT gateway costs have spiked and an engineer must investigate the traffic traversing the NAT gateway. Which options can be used to analyze NAT gateway traffic? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable VPC Flow Logs for the NAT gateway's ENI, publish the logs to an Amazon CloudWatch Logs log group, and use CloudWatch Logs Insights to query and analyze the logs., Enable VPC Flow Logs for the NAT gateway's ENI and publish the logs to an Amazon S3 bucket. Create a table for the S3 bucket in Amazon Athena and use Athena to query and analyze the logs..
Why this is the answer
VPC Flow Logs capture information about IP traffic going to and from network interfaces, including the NAT gateway's Elastic Network Interface (ENI). These logs can be published to CloudWatch Logs for real-time analysis with CloudWatch Logs Insights or to an S3 bucket for long-term storage and querying with Amazon Athena. Both options provide detailed traffic visibility to identify the source of increased NAT gateway costs. NAT gateways do not have native "access logs" that can be enabled; this is a fictitious option. Traffic Mirroring is used for deep packet inspection and security analysis, not for general traffic flow analysis and cost optimization, and it incurs additional costs and complexity that are not ideal for this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed