VPC Flow Logs Flashcards

1
Q

Where can Flow Logs be stored

A

Cloudwatch or S3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What levels are monitored on a flow log

A

VPC, Network, Subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Approx Capture window

A

10min

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ARP

A

address resolution protocol

the software address (IP address) of the host or computer connected to the network needs to be translated to a hardware address (MAC address). Without ARP, a host would not be able to figure out the hardware address of another host.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Traffic Mirroring

A

Mirroring gives you direct access to the network packets flowing through your VPC to help analyze network traffic and compare it to VPC Flow Log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Traffic Mirroring Source

A

Network interface of an Amazon EC2 instance where AWS copies the network traffic from. VPC Traffic Mirroring supports the use of Elastic Network Interfaces (ENIs) as mirror sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Traffic Mirroring Target

A

A network interface or a network load balancer.

network interface of another EC2 instance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Traffic Mirror Filter

A

set of rules that defines the traffic that is copied in a traffic mirror session.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Wireshark

A

detecting and decrypting network traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What traffic can you filter in a VPC flow log?

A

Accepted and Rejected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly