A SysOps admin enabled VPC Flow Logs to deliver data to Amazon CloudWatch Logs. After inspecting the CloudWatch Logs, the admin sees fewer packets than expected. Comparing those logs with packet captures taken from the on-premises network, the admin suspects the flow logs are missing some traffic. Which of the following could explain the discrepancy?
Choose an answer
Tap an option to check your answer.
Correct answer: VPC Flow Logs do not record traffic that originates from on-premises hosts and traverses into a VPC..
Why this is the answer
VPC Flow Logs capture IP traffic information for network interfaces within a VPC. However, they specifically do not capture traffic that originates from outside the VPC and traverses into it, such as traffic from on-premises hosts. This is a known limitation and explains why the admin sees fewer packets than expected compared to on-premises captures. CloudWatch Logs throttling is unlikely to cause a consistent discrepancy in specific traffic types. An incorrect IAM role trust policy would likely prevent any logs from being delivered, not just a subset. If the VPC Flow Log resource were still initializing, no logs or very few logs would be present, not just missing specific traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed