VPC Flow-Log Flashcards
1
Q
VPC FLowLog captures Packets, Segments, or data?
A
only captures Packet meta-data and not data and not a packet data content.
Packet content inspection can only be done using packet sniffers
2
Q
Flowlogs Architecture
A
Attaching Virtual Monitors to a VPC
It can be applied to
-
VPC Level
Network Interface in every subnet within that vpc -
Subnet Level
every Interface within a Particular Subnet -
Network Interface Level
Directly on a Network interface
3
Q
Flowlogs Latency
A
Flowlogs is not realtime
4
Q
Vpc Flowlog Integrations
A
- s3
- CLoudwatch Logs
- CLoudtrail
5
Q
Notable Protocols in VPC Flowlogs
A
Popular Protocol Number to take note of:
IMP=1,
TCP=6,
UDP=17
6
Q
A