A Site-to-Site VPN connects an on-premises network to a VPC. You launched a Windows EC2 instance with only a private IP in a private subnet. The instance’s security group allows inbound RDP from the on-premises CIDR and the on-prem firewall permits RDP over the VPN, but users time out when trying to RDP to the instance. What should you do to troubleshoot the connectivity problem?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable VPC Flow Logs for the ENI of the EC2 instance to look for rejected or dropped traffic..
Why this is the answer
VPC Flow Logs capture information about IP traffic going to and from network interfaces in your VPC. Enabling Flow Logs on the EC2 instance's Elastic Network Interface (ENI) will show if traffic from the on-premises network is reaching the instance and if it's being accepted or rejected. This is crucial for diagnosing network connectivity issues like RDP timeouts. CloudWatch Logs on the OS would only show traffic that reaches the OS, not network-level blocks. CloudWatch Logs for the VPN connection would show VPN tunnel status but not specific packet flow to the instance. EC2 Instance Connect is an alternative access method, not a troubleshooting step for the current problem.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed