ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 11 - FCP_WCS_AD-7.4 discussion

Report
Export

Which three statements are correct about VPC flow logs? (Choose three.)

A.
Flow logs do not capture traffic to and from 169.254.169.254 for instance metadata.
Answers
A.
Flow logs do not capture traffic to and from 169.254.169.254 for instance metadata.
B.
Flow logs do not capture DHCP traffic.
Answers
B.
Flow logs do not capture DHCP traffic.
C.
Flow logs can capture traffic to the reserved IP address for the default VPC router.
Answers
C.
Flow logs can capture traffic to the reserved IP address for the default VPC router.
D.
Flow logs can be used as a security tool to monitor the traffic that is reaching the instance.
Answers
D.
Flow logs can be used as a security tool to monitor the traffic that is reaching the instance.
E.
Flow logs can capture real-time log streams for the network interfaces.
Answers
E.
Flow logs can capture real-time log streams for the network interfaces.
Suggested answer: A, B, D

Explanation:

Instance Metadata Traffic:

VPC flow logs do not capture traffic to and from the link-local address 169.254.169.254, which is used for accessing instance metadata (Option A).

DHCP Traffic:

DHCP traffic is not captured by VPC flow logs. This is because DHCP relies on broadcast and multicast traffic, which is excluded from flow logs (Option B).

Security Monitoring:

VPC flow logs can be used as a security tool to monitor the traffic that is reaching the instances. By analyzing the flow logs, administrators can detect suspicious activities and troubleshoot connectivity issues (Option D).

Other Considerations:

Option C is incorrect because flow logs do capture traffic to the reserved IP address of the default VPC router.

Option E is incorrect as VPC flow logs do not provide real-time log streams but rather capture data at intervals and deliver them to CloudWatch or S3.

AWS VPC Flow Logs Documentation: VPC Flow Logs

AWS Networking and Security: AWS Security Monitoring

asked 18/09/2024
Idan Bar-On
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first