VPC Flow Logs Flashcards
1
Q
What are VPC Flow Logs?
A
Information about the IP traffic going to and from network interfaces in your VPC.
2
Q
Where is VPC Flow Log Data stored?
A
Flow log data is stored using Amazon CloudWatch Logs
3
Q
At what levels can VPC flow logs be created?
A
- VPC Level
- Subnet Level
- Network Interface Level (ENIs)
4
Q
Can you enable flow logs for a peered VPC?
A
Only if the peered VPC is in your account
5
Q
Can you attach tags to VPC flow logs?
A
Yes
6
Q
After creating a VPC flow log, can you change its configuration?
A
No
7
Q
What type of IP traffic might not be monitored by VPC Flow logs?
A
- Traffic generatd by instances when they contact the Amazon DNS server
- If you use your own DNS server, traffic to it <em>will</em> be logged
- Traffic generated by Windows instances for Amazon Windows license activation
- Traffic to and from 169.254.269.254 for instance metadata
- DHCP Traffic
- Traffic to the reserved IP address for the default VPC router
8
Q
What does DHCP stand for?
A
Dynamic Host Configuration Protocol