An application in a VPC uses a NAT gateway for outbound internet access. A network engineer observes a high volume of suspicious outbound traffic from the VPC to IP addresses on a deny list. The engineer needs to determine which AWS resources are producing that traffic while keeping costs and administrative effort low. Which approach satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable VPC Flow Logs and publish the logs to an Amazon CloudWatch Logs log group. Use CloudWatch Logs Insights to query the flow logs and identify which AWS resources are generating the suspicious traffic..
Why this is the answer
Enabling VPC Flow Logs and publishing them to CloudWatch Logs, then using CloudWatch Logs Insights, is the most cost-effective and lowest administrative effort solution. Flow Logs capture metadata about IP traffic, including source and destination IPs, ports, and bytes transferred, which is exactly what's needed to identify the source of suspicious outbound traffic. CloudWatch Logs Insights provides a powerful, serverless query language to analyze these logs directly, avoiding the overhead of deploying and managing additional infrastructure. Launching an EC2 instance for Traffic Mirroring is more complex and costly, requiring manual setup and analysis tools. Deploying a SIEM solution involves significant administrative overhead and cost for the SIEM itself. Streaming to Kinesis, then S3, and querying with Athena, while powerful, introduces more services and complexity than necessary for this specific task, increasing both cost and administrative effort.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed