VPC Flow Logs Flashcards

1
Q

What are VPC Flow Logs?

A

Information about the IP traffic going to and from network interfaces in your VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Where is VPC Flow Log Data stored?

A

Flow log data is stored using Amazon CloudWatch Logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

At what levels can VPC flow logs be created?

A
  • VPC Level
  • Subnet Level
  • Network Interface Level (ENIs)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can you enable flow logs for a peered VPC?

A

Only if the peered VPC is in your account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can you attach tags to VPC flow logs?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

After creating a VPC flow log, can you change its configuration?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What type of IP traffic might not be monitored by VPC Flow logs?

A
  • Traffic generatd by instances when they contact the Amazon DNS server
    • If you use your own DNS server, traffic to it <em>will</em> be logged
  • Traffic generated by Windows instances for Amazon Windows license activation
  • Traffic to and from 169.254.269.254 for instance metadata
  • DHCP Traffic
  • Traffic to the reserved IP address for the default VPC router
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does DHCP stand for?

A

Dynamic Host Configuration Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly