Q20Network Security, Compliance, and Governance
A company deployed an application in a VPC that uses a NAT gateway for outbound internet traffic. A network engineer observes a large volume of suspicious network traffic leaving the VPC over the internet for IP addresses on a deny list. The engineer must implement a solution to identify which AWS resources are producing the suspicious traffic. The solution must minimize cost and administrative overhead. Which solution meets these requirements?
← → navigate · a answer
Community votes
Discussion · 10
9
C) ensures - The solution must minimize cost and administrative overhead
C 8
VPC flow logs capture information about the IP traffic going to and from network interfaces in a VPC. They provide details such as source and destination IP addresses, ports, and protocols.
Publishing the VPC flow logs to a log group in Amazon CloudWatch Logs (Option C) allows for centralized and easy access to the flow log data.
CloudWatch Logs Insights can be used to query the flow logs efficiently and identify the AWS resources that are generating the suspicious traffic.
This solution minimizes cost by leveraging existing AWS services (CloudWatch Logs) and has lower administrative overhead compared to setting up custom streaming solutions (such as Amazon Kinesis) or deploying additional instances (as in Option A).
Options A, B, and D introduce additional complexity and may have higher associated costs or administrative overhead compared to using CloudWatch Logs Insights for analyzing VPC flow logs.
C 4
C is the correct answer.
VPC flow logs (with custom format to have "pkt-srcaddr" & "pkt-dstaddr" since it goes via NAT GW).
Direct it to CloudWatch Logs, and use CW Logs Insights for querying and visualization.
C 3
No doubt it is C, it is simple to implement (even temporarily) and is affordable.
C 2
C. " The solution must minimize cost and administrative overhead."
C 2
C is the simples
2
CCCCCCCCC
2
C - correct.
C 1
C is the correct answer.
C 1
Lowest cost