While analyzing VPC Flow Logs to debug connectivity, an administrator notices there are no entries for rejected traffic. What action should be taken to ensure the logs capture all traffic, including rejected packets?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new flow log and set its filter to capture all traffic..
Why this is the answer
The correct answer is to create a new flow log and set its filter to capture all traffic. VPC Flow Logs are immutable after creation. You cannot modify an existing flow log's configuration, including its filter settings. To capture rejected traffic, a new flow log must be created with the appropriate filter (e.g., "ALL" or "REJECT"). Creating a new flow log and using a custom log record format would allow for specific fields but wouldn't address the missing rejected traffic unless the filter was also set correctly. Editing the current flow log is not possible because flow logs cannot be modified once created.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed